logo

Shining a Light in the Dark – How Binary Defense…

ID: 9c180518-b0f8-5ebd-a350-8235e3b75f26

STIX ID: report--9c180518-b0f8-5ebd-a350-8235e3b75f26

Feed Name: Binary Defense Blog

Threat Score
70/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

Binary Defense and TrustedSec describe an intrusion in which a China-nexus threat actor compromised three publicly accessible AIX servers (using default Apache AXIS admin credentials), uploaded an AxisInvoker web shell, staged FRP reverse proxy and SSH keys for persistence, conducted Active Directory reconnaissance and NTLM relay, and attempted to dump LSASS on a Windows host in August 2024; detection in the managed Windows environment prevented full credential exfiltration. The report catalogs IOCs and TTPs, highlights shadow IT and unmanaged legacy systems as attack vectors, and recommends comprehensive asset visibility and managed detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.