Blog · Threat intel · 2026-10-02 · 14 min

Operation Open Ledger: an AI-assembled crew exfiltrating ERP data from Spanish SMBs

Open directories are where attackers leak too. On 89.124.67.72 an intrusion crew left its entire working environment exposed to the internet, and we recovered 10,428 files: the operator's shell history, a custom Microsoft Dynamics 365 Business Central exfiltration pipeline, a six-product enterprise exploit kit, a full Active Directory arsenal, a Sliver C2, a Monero miner, and 15 GB of data stolen from a cluster of Spanish small businesses. The tradecraft is Russian-speaking and visibly AI-assisted. This report is built from that corpus.

10,428
files recovered
15 GB
stolen data
10
victim organisations
6
products weaponised
24
offensive tools
Handling note. Victim organisations are anonymised to entity types; specific names and localities are withheld. Live credentials recovered in the corpus (an Azure app secret, private keys, API tokens) and personal data (payment-card numbers, IBANs, health records) are redacted throughout and are not reproduced here. Exploit techniques are described for defenders; working payloads are not republished.

Key findings

  • One exposed server, the whole operation. 10,428 files across the crew's working tree, shell history included, recovered from an open directory the operator exposed themselves.
  • Cloud-API exfiltration, not malware. The crew stole an Azure service-principal secret from a victim's exposed git repository (via gitleaks), minted OAuth tokens, and bulk-dumped every tenant through the Business Central REST API with a purpose-built pipeline (bc_full_dump.py / bc_export.sh, versioned to v2.0.2, with run logs).
  • A six-product exploit kit. Custom modules for SonicWall SMA1000 (CVE-2026-15409/15410, CVSS 10), JetBrains TeamCity (CVE-2026-63077), BeyondTrust (CVE-2026-1731), KEMP LoadMaster (CVE-2026-8037), SmarterMail (CVE-2026-24423) and an on-prem SharePoint key-dump.
  • Full Active Directory arsenal. 24 tools including mimikatz, secretsdump, DCSync, BloodHound, impacket, responder, ntlmrelayx and certipy, plus Sliver, Havoc and Cobalt Strike C2, chisel/gost/ngrok tunneling, and an xmrig Monero miner.
  • Assembled, not authored, and AI-assisted. The operator drives the work through an opencode AI agent; the borrowed PoCs are a polyglot of English, Russian and Chinese, one README credits ChatGPT. Running these tools establishes use, not authorship.
  • Data at scale. 15 GB from 10 Spanish SMBs: full ERP tenants plus payment-card numbers, IBANs and health records.

Discovery

huntback indexes malicious open directories across high-risk hosting and bulletproof ASN space, and correlates them with attacker activity on our deception network. This host, 89.124.67.72 at SERVERS TECH FZCO (AS216071) in The Netherlands, surfaced as an open HTTP directory and was promoted to a full harvest because its listing scored unambiguously malicious: offensive tooling, an exploit-labelled payload and a Sliver artifact next to bulk ERP exports is not something a legitimate server exposes. We recovered 10,428 files and classified the contents automatically, extracting secrets, victim identifiers, tooling and language markers into the dossier this report is built from. Our sensor history places the host between 2026-09-28 and 2026-10-01.

Attack chain

Two paths run from the same working directory. A cloud path turns stolen credentials into a clean API dump of each victim's ERP; an intrusion path exploits exposed enterprise appliances and pivots through Active Directory. Both feed the same loot tree, sorted one folder per victim.

1
OSINT & recon
2
Secret theft (gitleaks)
3
BC API token mint
4
ERP bulk exfil
5
Appliance exploit + AD pivot
6
C2, mining, loot sort

The operator's shell history shows the sequence directly: dirsearch sweeps of a target dental company's subdomains, then a working folder /opt/pentest/findings/spain-dental-osint/ holding 02-infra-map.md, a gitleaks-report.json over a recovered git repository, and a finding file literally named 03-CRITICAL-azure-bc-creds.md.

The exfiltration pipeline

The theft needs no malware on the victim. From the leaked git repository the crew recovered an Azure Entra ID application's client credentials, then ran the standard OAuth client-credentials grant to mint tokens and read the Business Central REST API directly, exactly as a legitimate integration would. The commands are preserved verbatim in the shell history (secrets and tenant redacted):

# 1. mint an app-only token with the stolen service-principal TOKEN=$(curl -s -X POST \ "https://login.microsoftonline.com/<tenant>/oauth2/v2.0/token" \ -d grant_type=client_credentials \ -d client_id=<redacted> -d client_secret=<redacted> \ -d scope=https://api.businesscentral.dynamics.com/.default) # 2. enumerate every company in the tenant curl -s -H "Authorization: Bearer $TOKEN" \ "https://api.businesscentral.dynamics.com/v2.0/<tenant>/Production/api/v2.0/companies" # 3. bulk-pull customers, ledgers, invoices per company .../companies(<id>)/customers · /generalLedgerEntries · /salesInvoices

Around that core sits a real engineering effort: bc_full_dump.py and bc_export.sh (kept in versioned backups up to v2.0.2, plus a bc_export_windowed.sh variant), an export step that lands the data as JSON/JSONL, and a stack of run logs (bc_full_dump_run1-3.log, bc_export_run.log) recording the pulls. A single generalLedgerEntries export reached 3.9 GB. This is the whole financial system of each business: customers, ledgers, invoices and attachments, not a sample.

The exploit arsenal

Parallel to the cloud theft, the crew carries a bundle of ready exploits for internet-facing enterprise appliances, each with its own README, and most tagged with a 2026 CVE on, or heading for, CISA's KEV list:

ProductCVETechniqueNotes
SonicWall SMA1000CVE-2026-15409 + CVE-2026-15410SSRF → Erlang RCE → root privescCVSS 10.0, CISA KEV
JetBrains TeamCityCVE-2026-63077Unauthenticated RCE (XStream deserialization)public Rapid7 PoC
BeyondTrust RS / PRACVE-2026-1731Pre-auth RCE (WebSocket argument injection)variant of CVE-2024-12356
Progress KEMP LoadMasterCVE-2026-8037Unauthenticated command injectionChinese-language PoC + nuclei template
SmarterMailCVE-2026-24423Unauth SSRF → RCE (ConnectToHub)PoC credited to ChatGPT
Microsoft SharePoint (on-prem)key-dump moduleMachine-key theft (ToolShell-class)PowerShell

The quality and provenance vary tellingly. The SonicWall module is a polished SSRF-to-root chain (tunnel through wsproxy into the appliance's internal Erlang distribution service, authenticate with a hardcoded cookie, execute via os:cmd, then escalate through an AMC path traversal). The TeamCity exploit is lifted from a public Rapid7 proof-of-concept. The KEMP and SmarterMail modules carry Chinese-language READMEs, and the SmarterMail one credits its authorship to ChatGPT. This is a kit assembled from many hands, not one author's work.

AI-assembled tradecraft

The shell history opens with the operator installing the opencode AI coding agent (curl -fsSL https://opencode.ai/install | bash), authenticating it and wiring up its config, and the 772 MB opencode.db sits in the loot. The crew drives reconnaissance, code and exploitation through that agent, and the borrowed PoCs, English, Russian and Chinese, one explicitly "made by ChatGPT", show the same pattern: large-language-model assembly of public offensive code into a working pipeline. Alongside it we recovered licensed OpenText / Fortify SAST and Metasploit Pro, nuclei (a 944-template scanning library), and katana. It is a commercial-grade, AI-accelerated operation, not a commodity botnet.

Post-exploitation toolkit

Once inside, the crew's kit is a textbook Active Directory chain: responder and ntlmrelayx for LLMNR/NBT-NS poisoning and relay; mimikatz, secretsdump and DCSync for credential theft; BloodHound / SharpHound and ldapsearch for mapping; impacket (psexec, wmiexec, smbexec, atexec) for lateral movement; certipy for ADCS certificate abuse; and winPEAS / linPEAS for privilege escalation. For command and control and egress we found Sliver (with a C2 config), Havoc and Cobalt Strike, tunnelled over chisel, gost and ngrok. And purely for profit, an xmrig Monero miner. Recovered secrets include 15 private keys, 10 Azure secrets, AWS and GCP keys, a GitHub token and JWTs.

A note on CVE scope

The operator's nuclei library references 944 distinct CVEs, most dating back as far as 2000. That number is the breadth of their scanning templates, not their kill list. The CVEs they actually weaponised with bespoke modules are the six in the table above. We separate the two deliberately: carrying a template is not exploiting a flaw, and conflating the scan library with confirmed exploitation would badly overstate the campaign. Where a README's CVE label is a variant or inherited identifier (BeyondTrust's CVE-2026-1731 is a sibling of CVE-2024-12356), we say so rather than taking the label at face value.

Who the victims are

The operator sorted exfiltration into one folder per victim, 10 distinct organisations, and the corpus tells us the type of entities involved without our needing to name them. The working directory is literally named spain-dental-osint; filenames and documents reference the Spanish commercial registry, regional towns, the national postal service and Spanish-language accounting terms, alongside S.L. (Sociedad Limitada) suffixes. The victims are Spanish small and mid-sized businesses, skewed toward dental and healthcare practices, plus an investment firm and other SMBs. We withhold the individual names and localities. Note the split: the operator is Russian-speaking; the targets are Spanish.

Per entity, the attacker pulled the complete Business Central tenant, and in several cases the document attachments too. The largest single victim alone accounts for 6.6 GB.

EntityFilesExfiltratedData types
Entity A246.6 GBcustomer database, document attachments, general ledger, inventory, purchase invoices
Entity B231.4 GBcredit memos, general ledger, inventory, purchase orders, sales invoices
Entity C91912 MBscanned documents
Entity D35630 MBscanned documents
Entity E17487 MBcredit memos, purchase invoices, purchase orders, sales invoices
Entity F119241 MBscanned documents
Entity G10232 MBcustomer database, general ledger, inventory, purchase invoices, sales invoices
Entity H24194 MBscanned documents
Entity I7181 MBcustomer database, general ledger, inventory, purchase invoices, purchase orders
Entity J155 MBsales invoices

What this means

A full Business Central dump plus intrusion access is a total compromise of a small business:

  • Personal-data breach (GDPR). Beyond the customers databases, the corpus holds thousands of payment-card numbers, hundreds of IBANs and health records, reportable under Spanish and EU law and acutely sensitive for the dental/healthcare cluster.
  • Invoice and BEC fraud. Full sales and purchase invoices, orders and supplier details enable supplier impersonation and payment redirection.
  • Extortion and financial exposure. The general ledger is every transaction, bank movement and balance, direct leverage and a complete map of the business.
  • Onward access. Stolen Azure app secrets, private keys and tokens mean the exposure outlives any single password reset until every credential is rotated.

Attribution

Tooling, directory names and operator notes are in Russian; the recovered vocabulary is offensive-operations language:

Captured termMeaning
ВАЖНОimportant
жертвvictims
пентестpentest
уязвимостvulnerability
фаззингfuzzing
эксплойтexploit

A working directory named project1488 also appears; 1488 is a numeric code associated with white-supremacist movements. We record it as an artifact of this operator's environment, not a confirmed group affiliation. Consistent with responsible practice, the Russian-language markers place a Russian-speaking operator or crew behind the infrastructure; language and borrowed-PoC artifacts are an attribution lead, not a link to a named group or state. The polyglot, AI-assembled toolkit is more consistent with an assembled crew than a single bespoke author.

Indicators of compromise

host    89.124.67.72 network SERVERS TECH FZCO / AS216071 (The Netherlands) seen    2026-09-28 to 2026-10-01 c2      Sliver (config recovered); Havoc and Cobalt Strike present mining xmrig (Monero) abuse   OAuth client-credentials against Business Central REST API from attacker IP
Notable fileSizeSHA-256
generalLedgerEntries.jsonl3.9 GB289df29fad549a46f7bc17cfb9b48cc1a188654b2c61faccd6b7a219a88d3ca2
salesInvoices.jsonl1.2 GB399e2ad2f6c914b7cd4f269ba6272c0a9e05afb30ac962b90fa386d3b8b80b16
OpenText_SAST_Fortify_Linux_26.1.0.tar.gz1.2 GB5ca72a168eda89ee7dc454af38bedb60295783f1e8ddb72cd050a9376a31399e
opencode.db772 MB323a7dee4e3d989877a9409e33fa7bae307569d77246f361b411fd7ea7605669
Fortify_Tools_25.4.0_Linux.tar.gz547 MBa0cbd1ae152d7f29cb87eda1e9be7d33603f08143cd801c1cea7f06a2798e5e8
Metasploit Pro 5.0.0 -L0dxG.rar309 MB58f357a942081264a1f8959ef4a474fb1c1b25608decb9eb0efaf406b4fca83c
generalLedgerEntries.json249 MBceea53c431f97de6b6081c4a40ebb942bc333f86c0166d75779ce773ab00bc30
generalLedgerEntries.jsonl222 MBb41e49cbcab79c43720aaf79b2de3f9a8543f4c2618df435cd32fb01489cee98

MITRE ATT&CK

TechniqueNameObserved via
T1595.002Vulnerability Scanningnuclei (944-template library), dirsearch
T1552.001Credentials in Filesgitleaks over an exposed git repo &rarr; Azure app secret
T1078.004Valid Accounts: Cloudstolen Azure service-principal, OAuth client-credentials
T1649Steal or Forge AD Certificatescertipy
T1003 / .001 / .006OS Credential Dumping (LSASS, DCSync)mimikatz, secretsdump, dcsync
T1087.002Account Discovery: DomainBloodHound, SharpHound, ldapsearch
T1021.002Remote Services: SMBimpacket psexec / wmiexec / smbexec / atexec
T1557.001LLMNR / NBT-NS Poisoning and Relayresponder, ntlmrelayx
T1071.001Web-protocol C2Sliver, Havoc, Cobalt Strike
T1572Protocol Tunnelingchisel, gost, ngrok
T1082System Information DiscoverywinPEAS, linPEAS
T1496Resource Hijackingxmrig (Monero miner)

Mitigations

  • Treat a leaked service-principal as a breach. Scan your own public and private repositories with gitleaks; a single committed Azure client secret was the entire entry point here. Rotate and vault app secrets, and prefer workload-identity federation over long-lived secrets.
  • Lock down the Business Central API. Least-privilege API scopes, conditional access on the token endpoint, and alerting on client-credentials grants and bulk OData reads (customers / generalLedgerEntries pulls) from unfamiliar IPs.
  • Patch the weaponised appliances now: SonicWall SMA1000 (CVE-2026-15409 / 15410), JetBrains TeamCity (CVE-2026-63077), BeyondTrust RS/PRA (CVE-2026-1731), KEMP LoadMaster (CVE-2026-8037), SmarterMail (CVE-2026-24423); rotate on-prem SharePoint machine keys.
  • Break the AD chain: disable LLMNR/NBT-NS, enforce SMB signing (relay), monitor DCSync-style replication from non-DCs, and audit ADCS templates (certipy).
  • Watch egress: Sliver/Havoc/Cobalt Strike beacons, chisel/gost/ngrok tunnels, and xmrig mining pools.

Summary

Operation Open Ledger is a compact illustration of where mid-tier intrusion has gone: a Russian-speaking operator, an AI agent, a folder of borrowed exploits, and a cloud API turned into a bulk-exfiltration tool against small businesses that will never see it in a log. They were undone by the oldest mistake, leaving their own server open, which is exactly how we find them. You can browse the running list of exposed C2 and malware infrastructure on live finds, see the IP profile for 89.124.67.72, or start free and hunt your own.

Hunt attacker infrastructure

Find exposed C2, open directories and loot servers from your own sensors, free.