
Zeta-9 Security Incident Report
During a CRISIS engagement, Warawut Manosong (as Chicken0248 agent) was deployed to investigate multiple security incidents across Zeta-9's infrastructure. The investigation revealed a full compromise of four critical assets, including:
- The FortiGate network firewall
- Hybrid cloud infrastructure (AWS and Azure)
- The JUMPHOST workstation
- The workstation of a key researcher
The first malicious activity was observed on September 16, 2025, targeting the FortiGate firewall to gain unauthorized access to the internal network. Subsequent actions by the adversary included:
- Exploitation of the Surveillance Storage Console to obtain JUMPHOST administrator credentials.
- Lateral movement to the JUMPHOST and exfiltration of AWS credentials.
- Unauthorized access and exfiltration of objects from hybrid cloud storage.
- Defacement of public-facing web assets hosted in Azure.
- Compromise of the researcher's workstation via a FileFix attack, leading to exfiltration of sensitive data, including the CURE: the final antidote against the ongoing zombie outbreak scenario.
This engagement demonstrates the high impact of coordinated attacks across on-premises and cloud environments, highlighting risks to both critical research and corporate operations.
Business & Stakeholder Impact
1. Strategic Impact: Confidentiality Breach
- Corporate secrets and credentials were exposed. The adversary extracted local administrator credentials from surveillance video footage, AWS secret values from parameter store, and sensitive datasets from both AWS S3 and Azure Blob storage.
- High-value intellectual property and internal R&D data stored in cloud repositories were accessed. This includes files belonging to ZETA-9's "Secret Division," implying possible loss of proprietary research materials.
- Brand trust compromised. The defacement of the public Azure Web App resulted in reputational damage, as stakeholders and clients may have observed tampered content displaying adversary-controlled messaging.
2. Operational Impact: Service Disruption & Persistence
- The adversary established persistent remote control via a Sliver C2 implant embedded into Dr. Frankenstein Code's PowerShell profile. This persistence mechanism could have allowed long-term access, unauthorized script execution, and continuous monitoring of internal operations.
- Automation and backup workflows on compromised cloud accounts may have been disrupted due to deleted or modified configurations during the exfiltration phase.
- Forensic indicators show data tampering and secure deletion (SDelete), suggesting permanent loss of original evidence and potential data corruption in the affected division.
3. Financial & Compliance Impact
- Potential Regulatory Exposure: The unauthorized access to personal and research data likely violates data protection obligations (GDPR/PDPA equivalents), exposing Zeta-9 to regulatory fines and reporting requirements.
- Incident Response and Recovery Costs: Containment, forensic imaging, cloud credential rotation, and rebuilding of affected environments will incur significant cost and downtime.
- Reputational and Market Impact: Investor confidence and partner relations may be affected due to public disclosure of the defacement and data leaks.
| Date/Time (UTC) | Event | Source |
|---|---|---|
| 2025-09-16 00:10:08 | First event observed of the adversary connecting to the firewall | FortiGate Syslog |
| 2025-09-16 00:17:36 | The adversary exploited CVE-2024-55591 | FortiGate Syslog |
| 2025-09-16 00:18:12 | The adversary connected to the VPN as zeta_adm user | FortiGate Syslog |
| 2025-09-16 00:19:37 | The adversary enumerated hosts within the network range 192.168.86.0/24 | FortiGate Syslog |
| 2025-09-24 01:08:58 | The adversary discovered the Surveillance Storage Console | Arkime |
| 2025-09-24 01:16:50 | The adversary exploited a SQL injection vulnerability on the Surveillance Storage Console webpage | Arkime |
| 2025-09-24 01:17:33 | The adversary downloaded a video containing the local administrator credential of JUMPHOST | Arkime |
| 2025-09-24 10:38:31 | The adversary performed lateral movement to JUMPHOST with a WMI-based technique using custom malware for AWS credential exfiltration | Memory dump |
| 2025-09-25 16:06:00 | First event on AWS by the adversary | AWS CloudTrail |
| 2025-09-25 16:15:00 | The adversary retrieved the secret value from zeta9/windows/admin-password | AWS CloudTrail |
| 2025-09-25 16:27:00 | The adversary retrieved AWS objects from S3 storage | AWS CloudTrail |
| 2025-09-25 16:38:07 | First event on Azure Storage Blob by the adversary | StorageBlobLogs |
| 2025-09-25 16:41:12 | The adversary retrieved objects from Azure Blob storage | StorageBlobLogs |
| 2025-09-25 16:50:00 | Azure Web App defacement | AppServiceHTTPLogs |
| 2025-09-27 11:17:33 | Dr. Frankenstein Code visited the defaced website, resulting in a FileFix attack and initial access to ZETA9-SECRETDIV | Microsoft Edge History |
| 2025-09-27 11:23:09 | The adversary created a PowerShell profile for Dr. Frankenstein Code | USN Journal |
| 2025-09-27 11:30:52 | The adversary cloned the Sliver C2 implant from MEGA | USN Journal, MEGA |
| 2025-09-27 11:34:18 | The adversary moved the Sliver C2 implant to C:\Users\Public\RunTimeBroker.exe | USN Journal |
| 2025-09-27 11:35:08 | The adversary added the Sliver C2 implant as persistence in the PowerShell profile of Dr. Frankenstein Code | USN Journal |
| 2025-09-27 15:49:58 | The adversary embedded the exfiltration zip file into an image file and deleted the original files from ZETA9-SECRETDIV with SDelete | USN Journal, Prefetch |
| 2025-09-28 02:20:47 | The adversary removed all entries from the TypedPaths registry key of Dr. Frankenstein Code's user profile to clear tracks | NTUSER.DAT |
Affected Systems & Devices
| Hostname/Device Name | IP Addresses | OS | Role |
|---|---|---|---|
| ProjectZ-fw | 38.68.134.215 | FortiOS | Firewall |
| — | 10.0.14.53 / 18.133.31.160 | Linux | Surveillance Storage Console |
| JUMPBOX | 192.168.1.148 / 192.168.86.2 | Windows | Jumphost |
| zeta9-research-portal.azurewebsites.net | N/A | Linux | Azure Web App |
| ZETA9-SECRETDIV | 192.168.45.128 | Windows 10 Pro | Dr. Frankenstein Code's workstation |
Affected Users
| Username | Compromised From | Details |
|---|---|---|
| zeta-adm | FortiGate (ProjectZ-fw) | CVE-2024-55591 and added user to VPN group |
| ghost | FortiGate (ProjectZ-fw) | CVE-2024-55591 |
| operator39 | Surveillance Storage Console | Local Administrator on JUMPBOX, credentials exfiltrated from storage console |
| VictorVenom | Jumpbox | IAMUser, credentials exfiltrated from Jumpbox |
| Dr.FrankensteinCode | ZETA9-SECRETDIV | Victim of FileFix attack |
| Dr.Helena | ZETA9-SECRETDIV | User on the same host as Dr.FrankensteinCode |
Files Exfiltrated
| File Name / File Path | Source |
|---|---|
cam06_ai_monitor_securityincident.mp4 | Arkime |
reports/threat-analysis-September-2025.json | AWS S3 Bucket (zombie-killer-antivirus) |
infrastructure/cloudformation/database-stack.txt | AWS S3 Bucket (zeta9-cloudaws-ops) |
secrets/api-keys/third-party-integrations.dat | AWS S3 Bucket (zeta9-cloudaws-ops) |
backups/database-backup-sept-24.tar.gz | AWS S3 Bucket (zeta9-cloudaws-ops) |
Subject-Zombie15-Experiment.pdf | AWS S3 Bucket (zombietesting) |
/zeta9researchdata/quantum-research-secrets/contracts/military-qc-2025.txt | Azure Storage Blob |
/zeta9researchdata/quantum-research-secrets/research/quantum-nexus-status.txt | Azure Storage Blob |
/zeta9researchdata/quantum-research-secrets/secretLAB/SecretLANConnection.txt | Azure Storage Blob |
/zeta9researchdata/quantum-research-secrets/secretLAB/SecretLabInfo.txt | Azure Storage Blob |
/zeta9researchdata/quantum-research-secrets/secretLAB/SecretNetworkVPN.txt | Azure Storage Blob |
/zeta9researchdata/quantum-research-secrets/secretLAB/AntiZombieSolution.txt | Azure Storage Blob |
C:\Users\Dr.FrankensteinCode\Desktop\confidential.png | Exfiltrated image file |
C:\Users\Dr.FrankensteinCode\Desktop\CURE.txt | Exfiltrated image file |
C:\Users\Dr.FrankensteinCode\Desktop\gunman.png | Exfiltrated image file |
C:\Users\Dr.FrankensteinCode\Desktop\Helena.txt | Exfiltrated image file |
C:\Users\Dr.FrankensteinCode\Desktop\test.txt | Exfiltrated image file |
C:\Users\Dr.FrankensteinCode\Desktop\outbreak.png | Exfiltrated image file |
Important File Deletion
| File Name / File Path | Source |
|---|---|
C:\Users\Dr.FrankensteinCode\Desktop\confidential.png | USN Journal |
C:\Users\Dr.FrankensteinCode\Desktop\CURE.txt | USN Journal |
C:\Users\Dr.FrankensteinCode\Desktop\gunman.png | USN Journal |
C:\Users\Dr.FrankensteinCode\Desktop\Helena.txt | USN Journal |
C:\Users\Dr.FrankensteinCode\Desktop\test.txt | USN Journal |
C:\Users\Dr.FrankensteinCode\Desktop\outbreak.png | USN Journal |
Evidence
| Evidence | Type | Details |
|---|---|---|
| FortiGate Syslog | Syslog / Log | Ingested in Graylog |
| Arkime network logs | Network Traffic | Ingested in Arkime |
| JUMPBOX-20250925-103855.raw | Memory dump | Jumpbox host |
| AWSCloudTrail.json | CloudTrail (AWS) | Ingested in Splunk |
| AppServiceHTTPLogs.json | AppServiceHTTPLogs (Azure) | Ingested in Splunk |
| StorageBlobLogs.json | StorageBlobLogs (Azure) | Ingested in Splunk |
| KAPE Triage | Triage Image | Triage image from ZETA9-SECRETDIV |

On September 16, 2025, the adversary identified Zeta-9's FortiGate Firewall exposed to the internet via its public IP address. The attacker's originating IP was recorded as 38[.]68[.]134[.]103.
Shortly afterward, the firewall logs captured evidence of an unauthorized administrator login performed through the FortiGate JSON console interface (jsconsole), which corresponds to the authentication bypass vulnerability CVE-2024-55591.

These events indicate that the attacker exploited the vulnerability to execute API calls locally via 127.0.0.1, bypassing normal authentication controls and logging in as the administrator account "ghost." Immediately after gaining administrative access, the attacker modified a user group (ZetaGroup) to include several new VPN accounts, establishing a persistent entry point into the internal network.

The adversary then leveraged these newly added credentials to initiate a VPN connection and access Zeta-9's internal environment without triggering perimeter authentication alerts. The adversary now had access to the internal network with an IP address of 10[.]1[.]1[.]10.

Once inside, the adversary conducted network reconnaissance within the 192.168.86.0/24 subnet, scanning for SMB (445/TCP), RPC/DCOM (135/TCP), and LDAP (389/TCP) services: typical indicators of host and domain enumeration activity.

This reconnaissance revealed the presence of a JUMPHOST system, which subsequently became the next stage of the attacker's lateral movement.

Another activity was observed on September 24, 2025. The adversary with an IP address of 91[.]90[.]124[.]21 had interacted with the Surveillance Storage Console.

The adversary attempted to conduct a SQL injection attack on the Surveillance Storage Console.

The adversary successfully exploited the SQL injection vulnerability on the Surveillance Storage Console and was able to download the storage object with an ID of 6.

The user-agent showed that the threat actor used PowerShell to manually exploit the SQL injection vulnerability and download storage object ID 6, which is the cam06_ai_monitor_securityincident.mp4 video file.

The credential of operator39 could be obtained within the video, which would be used for lateral movement to JUMPBOX.

With the credential obtained from the Surveillance Storage Console, the adversary conducted a WMI-based lateral movement technique to inject a malicious DLL into the legitimate more.com process.

The adversary deployed the custom malware (Deaddrop.dll) on this jumphost, which retrieved its configuration like the ChaCha20 key and nonce from the repository hosted on codeberg.org.

The custom malware exfiltrated data via dnshook[.]site by appending a subdomain with the BASE32-encoded ChaCha20-Poly1305 ciphertext.

The AWS credential was stolen and would be used to access the hybrid cloud environment.

Credentials exfiltrated from the jump box were used by the adversary to sign in to AWS as "VictorVenom." The activity was observed from 172[.]235[.]129[.]221 on September 25, 2025, in the AWS CloudTrail log.

After gaining access, the adversary invoked the GetSecretValue API to retrieve the secret zeta9/windows/admin-password, which likely contains Windows administrative credentials.

Subsequently, the adversary downloaded 5 objects from 3 different Amazon S3 buckets including a database backup, secret API key, threat analysis report, and the Zombie 15 experiment.

After that, the adversary activity was observed from the website hosted on Azure, which was restricted to administrator-level access only. The adversary used the cmd parameter to run system commands to request an OAuth access token from Azure Managed Identity using a secret that was possibly obtained from an AWS S3 object.

Using the acquired OAuth token, the adversary accessed the quantum-research-secrets Azure Blob Storage container and exfiltrated sensitive files including contracts, research, and confidential laboratory information.

The adversary was observed retrieving malicious content from hxxps[://]pastebin[.]com/raw/sBEs83q3, which was then used to overwrite /home/site/wwwroot/public/index.html. This action resulted in the defacement of the main index page of zeta9-research-portal.azurewebsites.net.

From the initial access to the AWS environment to website defacement, the adversary only took 44 minutes from 16:06:00 UTC to 16:50:00 UTC. This rapid attack sequence demonstrated sophisticated knowledge of both AWS and Azure environments, indicating a well-planned and executed intrusion.

On September 27, 2025, Dr. Frankenstein Code visited a compromised website that had been defaced by the adversary, which led to a FileFix attack being successfully deployed on this workstation.

Upon executing the malicious PowerShell command from the defaced website, the command fetched another PowerShell script payload from hxxps[://]gist[.]githubusercontent[.]com/a1l4m/.../Microsoft[.]PowerShell[.]DataV4Adapter[.]ps1 and this script fetched the hex-encoded shellcode from hxxps[://]gist[.]githubusercontent[.]com/a1l4m/.../IamTheDanger[.]txt and executed it, which established a reverse shell connection to the adversary on 35[.]158[.]153[.]237 on port 34651.

The first command after establishing the reverse shell connection was observed from the adversary at 11:18:33 with the whoami command to determine the level of access on this workstation. Subsequently, we observed more activity from the adversary, which utilized rclone to transfer the Sliver C2 implant from MEGA drive.

The Sliver C2 implant was originally named sapi.cpl as downloaded from MEGA drive.

The adversary then renamed it to RunTimeBroker.exe and moved it to C:\Users\Public.

The adversary achieved persistence on this workstation by creating a PowerShell profile, as observed in the USN Journal.

The Sliver C2 implant execution was observed several times after PowerShell execution. Afterward, KillTheCURE.exe and sdelete.exe were executed from the same folder at C:\Users\Dr.FrankensteinCode\AppData\Local\CureKiller\CureKiller around 15:49:58 ~ 15:49:59.

KillTheCURE.exe and sdelete.exe along with several DLLs were observed being extracted from the CUREKiller.zip file that was downloaded with the living-off-the-land binary certutil.exe, and the Exfiltration_data.zip was created after the execution of KillTheCURE.exe.

CUREKiller.zip was downloaded from GitHub. This attachment was likely uploaded within an issue, a pull request, or a comment on GitHub.

The adversary used sdelete to permanently delete all original files that had already been copied to the user's temporary folder.

SDelete.exe execution was observed immediately after the execution of KillTheCURE.exe, which deleted 6 files on the desktop:
C:\Users\Dr.FrankensteinCode\Desktop\confidential.pngC:\Users\Dr.FrankensteinCode\Desktop\CURE.txtC:\Users\Dr.FrankensteinCode\Desktop\gunman.pngC:\Users\Dr.FrankensteinCode\Desktop\Helena.txtC:\Users\Dr.FrankensteinCode\Desktop\test.txtC:\Users\Dr.FrankensteinCode\Desktop\outbreak.png

After finishing the deletion, an image file was created with the Exfiltration_data.zip embedded, which contained the 6 files stolen from this workstation.


KillTheCURE.exe was designed to search for .png and .txt files located in the Downloads and Desktop folders of the current user and copy them to the Temp folder, zip them to Exfiltrated_data.zip, embed the archive in BetterCallSaul.png, send the image to 36[.]157[.]123[.]216 with an HTTP POST request, and finally use sdelete.exe to completely remove the original files from the workstation.
The adversary also utilized rclone as a fallback, and we successfully obtained the image file from the MEGA drive of the adversary.


After the exfiltration phase, the adversary cleared all tracks that could be traced back to them.

Additionally, a Wing FTP Server exploitation script (CVE-2025-47812) was also found on the MEGA drive and on this workstation, which indicates that the adversary also attempted to exploit the Wing FTP Server running on this workstation.

On September 28, 2025, the adversary cleared 5 different logs, and a netcat executable was also observed before the log clearing event.

The registry key that contains the information indicating the FileFix attack was deleted at 2025-09-28 02:20:47.

All of them were eventually deleted by the adversary at the end.
38[.]68[.]134[.]103: IP used by the adversary to access FortiGate firewall91[.]90[.]124[.]21: IP used by the adversary to attack the Storage Console172[.]235[.]129[.]221: IP used by the adversary to attack hybrid cloud infrastructure (AWS + Azure)35[.]158[.]153[.]237:34651: IP used by the adversary for the ClickFix attack63[.]178[.]44[.]21:8838: IP used by the Sliver implant as persistence36[.]157[.]123[.]216: IP used by KillTheCURE.exe payload to exfiltrate fileshxxps[://]pastebin[.]com/raw/sBEs83q3: Pastebin used to retrieve source code of the FileFix webpagezeta9-research-portal.azurewebsites.net: Compromised Azure Web Appzeta9/windows/admin-password: Compromised AWS Secrethxxps[://]gist[.]githubusercontent[.]com/a1l4m/.../Microsoft[.]PowerShell[.]DataV4Adapter[.]ps1: ClickFix payload stage 0hxxps[://]gist[.]githubusercontent[.]com/a1l4m/.../IamTheDanger[.]txt: URL that hosted the shellcodehxxps[://]github[.]com/user-attachments/files/22441452/CUREKiller[.]zip: GitHub link hosting the exfiltration binaryaboallam480+2@gmail.com: MEGA account00darksideofme00+2@gmail.com: MEGA account2c327fdbaf65f8626f76858206a18a81790c5233917396e96f12d4cdea06fc7b: Sliver implante8fbec25db4f9d95b5e8f41cca51a4b32be8674a4dea7a45b6f7aeb22dbc38db: Netcat binarycc84a7c2e28dddcab7143ef57429dbd9f45cb61cec86ac1d0134658d5d47170c: WingFTP CVE exploitation script93997160b7091a043bc7cd8241f4e7d73ba0c6903337d2379e8b3d3cbb855885: CUREKiller.zip367555ad82dbca5d7607b46720b569e5ee04aa01c3d31e32451238a9c580268a: KillTheCURE.exee1f7f9741f16c55c7d90e020812680673dfe3dcf87f43f722be8349aada213f2: sdelete.exeImmediate Tactical Fixes
- Contain all compromised devices
- Isolate the researcher's workstation, JUMPHOST, and any affected servers from the network.
- Disable persistence mechanisms (e.g., Sliver C2 implants, malicious PowerShell profiles).
- Remove unauthorized accounts and VPN sessions
- Delete or disable the "ghost" VPN user from the FortiGate firewall.
- Rotate all exposed credentials, including local admin, cloud, and service accounts.
- Patch and update critical infrastructure
- Upgrade FortiOS to the latest secure version.
- Ensure all servers, endpoints, and appliances have current security patches applied.
- Verify and restore data integrity
- Check cloud storage (AWS S3, Azure Blob) for unauthorized changes.
- Restore deleted or tampered files from backups where possible.
Strategic Improvements
- Adopt a Zero Trust security model
- Implement least privilege access, micro-segmentation, and continuous authentication.
- Ensure multi-factor authentication (MFA) is enforced for all privileged accounts.
- Enhance monitoring and detection
- Deploy or improve SIEM/XDR to monitor lateral movement, anomalous cloud access, and endpoint compromise.
- Integrate real-time alerting for critical events across both on-premises and cloud environments.
- Strengthen cloud security posture
- Enforce IAM best practices: rotate keys, implement role-based access, and audit cloud accounts regularly.
- Enable logging and versioning for all cloud storage objects to detect unauthorized access or deletions.
- Incident response readiness
- Maintain an updated playbook for advanced persistent threats targeting multi-cloud environments.
- Conduct tabletop exercises simulating full compromise scenarios to improve team readiness.
Splunk Queries
index=* "userIdentity.accessKeyId"=AKIA3EBEV4OQF3XCXJ5S | sort _time
index=* "userIdentity.accessKeyId"=AKIA3EBEV4OQF3XCXJ5S eventName=GetObject | sort _time | table requestParameters.bucketName, requestParameters.key
index=* "172.235.129.221" sourcetype=StorageBlobLogs | sort _time
index=* "172.235.129.221" sourcetype=StorageBlobLogs | sort _time | table AuthenticationType, OperationName, ObjectKeyRclone Configuration File

File Inside Adversary's MEGA Account

File Recovery
A Python script was used to recover files from the steganographic image created by the adversary:
# extractor.py
# Requires: Pillow (PIL)
# Usage: python extractor.py hidden.png recovered.bin
import sys
from PIL import Image
import zlib
import struct
def read_rgba_bytes(png_path):
img = Image.open(png_path)
img = img.convert("RGBA")
data = img.tobytes() # row-major RGBA
return data
def extract(png_path, out_path):
data = read_rgba_bytes(png_path)
if len(data) < 16:
raise ValueError("PNG too small or not containing embedded data.")
header = data[:16]
crc32_field, key_field_lo, orig_size = struct.unpack("<I Q I", header)
key = struct.pack("<Q", key_field_lo)[:4]
original_size = orig_size
encrypted = data[16:16+original_size]
if len(encrypted) < original_size:
raise ValueError("PNG does not contain full payload (truncated).")
key_u32 = key
block12 = key + b'\x00\x00\x00\x00' + struct.pack("<I", original_size)
check_crc = zlib.crc32(block12) & 0xFFFFFFFF
if check_crc != crc32_field:
print("Warning: CRC mismatch (payload integrity check failed).")
key_bytes = key
out = bytearray()
for i, b in enumerate(encrypted):
out.append(b ^ key_bytes[i % 4])
with open(out_path, "wb") as f:
f.write(out)
print(f"Wrote {len(out)} bytes to {out_path}")
if __name__ == "__main__":
if len(sys.argv) != 3:
print("Usage: python extractor.py hidden.png recovered.bin")
sys.exit(1)
extract(sys.argv[1], sys.argv[2])
By running the script, we can obtain the zip file that contains the 6 files that were exfiltrated by the adversary.