Third piece in the pitboss series: the second wave's collector at 213.209.159.55 is still live, still serving per-target droppers, and its code evolved from gen-3 to v19-plus while I watched. Full teardown of the forced HA-failover logic and the three-channel C2 (one-shot relay, 15-second pull tasking with output return, HTTP front), why the exfil side is write-only and what that means for victims, the nine-month attack history of the address (January port scans, February .env probes, March .git probes via Go-http-client, Ligolo-ng tunnels in October), a correction to my own domain-aging claim, and the detection set that matters now.
grep -rl "Threat Intelligence" ./posts
#Threat Intelligence
3 matches
A follow-up investigation to the pitboss teardown: pivoting the public malware corpus on the passwords, tokens, and placeholder strings extracted from the campaign samples turns two copycat bundles into a twenty-deployment operation with three code generations, surfaces chisel on the exfil host, doubles the Platypus enrollment count, and recovers a victim's implant config that phoned a lab address that does not exist. With the pivot methodology, its traps (the MD5 test vector that fakes attribution), and expanded IOCs.
Full teardown of the September 2026 NetScaler ADC/Gateway zero-day campaign: the ns_monuploadd_err.pl log-poisoning root cause analyzed line by line from firmware, the watchTowr DTLS heap-overflow PoC dissected down to its setcontext/ROP chain, and the complete payload landscape grounded in first-hand analysis of 18 in-the-wild campaign samples: the dual-mode webshell installers, update_c08937.pl with its plaintext passwords, the nsmon.pl cron bind shell no vendor named, Platypus enrollment certificates that date the C2 infrastructure to September 2, and a post-disclosure WHIPSHOT/SLAPSHOT copycat kit. With detection and eradication guidance.