logo

CNACOM Open Source Exploitation via Strategic Web Compromise

ID: 87310770-6924-5080-b2af-c19df10ab60a

STIX ID: report--87310770-6924-5080-b2af-c19df10ab60a

Feed Name: Zscaler Security Research Blog

Threat Score
85/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This technical report describes the CNACOM campaign: a web-based, targeted exploitation operation that used CVE-2016-0189 (with apparent sandbox escape via CVE-2015-0116) delivered from malicious landing pages to infect visitors from specific Taiwanese government network ranges, ultimately deploying an IXESHE/AES backdoor (linked to APT12/Numbered Panda). The analysis details the infection flow, host fingerprinting logic, persistence mechanism, C2 callback patterns and SSL use, and supplies IOCs including filename, MD5 and a C2 IP.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.