Operation Open Ledger: an AI-assembled crew exfiltrating ERP data from Spanish SMBs
Open directories are where attackers leak too. On 89.124.67.72 an intrusion crew left its entire working environment exposed to the internet, and we recovered 10,428 files: the operator's shell history, a custom Microsoft Dynamics 365 Business Central exfiltration pipeline, a six-product enterprise exploit kit, a full Active Directory arsenal, a Sliver C2, a Monero miner, and 15 GB of data stolen from a cluster of Spanish small businesses. The tradecraft is Russian-speaking and visibly AI-assisted. This report is built from that corpus.
Contents
Key findings
- One exposed server, the whole operation. 10,428 files across the crew's working tree, shell history included, recovered from an open directory the operator exposed themselves.
- Cloud-API exfiltration, not malware. The crew stole an Azure service-principal secret from a victim's exposed git repository (via
gitleaks), minted OAuth tokens, and bulk-dumped every tenant through the Business Central REST API with a purpose-built pipeline (bc_full_dump.py/bc_export.sh, versioned to v2.0.2, with run logs). - A six-product exploit kit. Custom modules for SonicWall SMA1000 (CVE-2026-15409/15410, CVSS 10), JetBrains TeamCity (CVE-2026-63077), BeyondTrust (CVE-2026-1731), KEMP LoadMaster (CVE-2026-8037), SmarterMail (CVE-2026-24423) and an on-prem SharePoint key-dump.
- Full Active Directory arsenal. 24 tools including mimikatz, secretsdump, DCSync, BloodHound, impacket, responder, ntlmrelayx and certipy, plus Sliver, Havoc and Cobalt Strike C2, chisel/gost/ngrok tunneling, and an xmrig Monero miner.
- Assembled, not authored, and AI-assisted. The operator drives the work through an opencode AI agent; the borrowed PoCs are a polyglot of English, Russian and Chinese, one README credits ChatGPT. Running these tools establishes use, not authorship.
- Data at scale. 15 GB from 10 Spanish SMBs: full ERP tenants plus payment-card numbers, IBANs and health records.
Discovery
huntback indexes malicious open directories across high-risk hosting and bulletproof ASN space, and correlates them with attacker activity on our deception network. This host, 89.124.67.72 at SERVERS TECH FZCO (AS216071) in The Netherlands, surfaced as an open HTTP directory and was promoted to a full harvest because its listing scored unambiguously malicious: offensive tooling, an exploit-labelled payload and a Sliver artifact next to bulk ERP exports is not something a legitimate server exposes. We recovered 10,428 files and classified the contents automatically, extracting secrets, victim identifiers, tooling and language markers into the dossier this report is built from. Our sensor history places the host between 2026-09-28 and 2026-10-01.
Attack chain
Two paths run from the same working directory. A cloud path turns stolen credentials into a clean API dump of each victim's ERP; an intrusion path exploits exposed enterprise appliances and pivots through Active Directory. Both feed the same loot tree, sorted one folder per victim.
The operator's shell history shows the sequence directly: dirsearch sweeps of a target dental company's subdomains, then a working folder /opt/pentest/findings/spain-dental-osint/ holding 02-infra-map.md, a gitleaks-report.json over a recovered git repository, and a finding file literally named 03-CRITICAL-azure-bc-creds.md.
The exfiltration pipeline
The theft needs no malware on the victim. From the leaked git repository the crew recovered an Azure Entra ID application's client credentials, then ran the standard OAuth client-credentials grant to mint tokens and read the Business Central REST API directly, exactly as a legitimate integration would. The commands are preserved verbatim in the shell history (secrets and tenant redacted):
Around that core sits a real engineering effort: bc_full_dump.py and bc_export.sh (kept in versioned backups up to v2.0.2, plus a bc_export_windowed.sh variant), an export step that lands the data as JSON/JSONL, and a stack of run logs (bc_full_dump_run1-3.log, bc_export_run.log) recording the pulls. A single generalLedgerEntries export reached 3.9 GB. This is the whole financial system of each business: customers, ledgers, invoices and attachments, not a sample.
The exploit arsenal
Parallel to the cloud theft, the crew carries a bundle of ready exploits for internet-facing enterprise appliances, each with its own README, and most tagged with a 2026 CVE on, or heading for, CISA's KEV list:
| Product | CVE | Technique | Notes |
|---|---|---|---|
| SonicWall SMA1000 | CVE-2026-15409 + CVE-2026-15410 | SSRF → Erlang RCE → root privesc | CVSS 10.0, CISA KEV |
| JetBrains TeamCity | CVE-2026-63077 | Unauthenticated RCE (XStream deserialization) | public Rapid7 PoC |
| BeyondTrust RS / PRA | CVE-2026-1731 | Pre-auth RCE (WebSocket argument injection) | variant of CVE-2024-12356 |
| Progress KEMP LoadMaster | CVE-2026-8037 | Unauthenticated command injection | Chinese-language PoC + nuclei template |
| SmarterMail | CVE-2026-24423 | Unauth SSRF → RCE (ConnectToHub) | PoC credited to ChatGPT |
| Microsoft SharePoint (on-prem) | key-dump module | Machine-key theft (ToolShell-class) | PowerShell |
The quality and provenance vary tellingly. The SonicWall module is a polished SSRF-to-root chain (tunnel through wsproxy into the appliance's internal Erlang distribution service, authenticate with a hardcoded cookie, execute via os:cmd, then escalate through an AMC path traversal). The TeamCity exploit is lifted from a public Rapid7 proof-of-concept. The KEMP and SmarterMail modules carry Chinese-language READMEs, and the SmarterMail one credits its authorship to ChatGPT. This is a kit assembled from many hands, not one author's work.
AI-assembled tradecraft
The shell history opens with the operator installing the opencode AI coding agent (curl -fsSL https://opencode.ai/install | bash), authenticating it and wiring up its config, and the 772 MB opencode.db sits in the loot. The crew drives reconnaissance, code and exploitation through that agent, and the borrowed PoCs, English, Russian and Chinese, one explicitly "made by ChatGPT", show the same pattern: large-language-model assembly of public offensive code into a working pipeline. Alongside it we recovered licensed OpenText / Fortify SAST and Metasploit Pro, nuclei (a 944-template scanning library), and katana. It is a commercial-grade, AI-accelerated operation, not a commodity botnet.
Post-exploitation toolkit
Once inside, the crew's kit is a textbook Active Directory chain: responder and ntlmrelayx for LLMNR/NBT-NS poisoning and relay; mimikatz, secretsdump and DCSync for credential theft; BloodHound / SharpHound and ldapsearch for mapping; impacket (psexec, wmiexec, smbexec, atexec) for lateral movement; certipy for ADCS certificate abuse; and winPEAS / linPEAS for privilege escalation. For command and control and egress we found Sliver (with a C2 config), Havoc and Cobalt Strike, tunnelled over chisel, gost and ngrok. And purely for profit, an xmrig Monero miner. Recovered secrets include 15 private keys, 10 Azure secrets, AWS and GCP keys, a GitHub token and JWTs.
A note on CVE scope
The operator's nuclei library references 944 distinct CVEs, most dating back as far as 2000. That number is the breadth of their scanning templates, not their kill list. The CVEs they actually weaponised with bespoke modules are the six in the table above. We separate the two deliberately: carrying a template is not exploiting a flaw, and conflating the scan library with confirmed exploitation would badly overstate the campaign. Where a README's CVE label is a variant or inherited identifier (BeyondTrust's CVE-2026-1731 is a sibling of CVE-2024-12356), we say so rather than taking the label at face value.
Who the victims are
The operator sorted exfiltration into one folder per victim, 10 distinct organisations, and the corpus tells us the type of entities involved without our needing to name them. The working directory is literally named spain-dental-osint; filenames and documents reference the Spanish commercial registry, regional towns, the national postal service and Spanish-language accounting terms, alongside S.L. (Sociedad Limitada) suffixes. The victims are Spanish small and mid-sized businesses, skewed toward dental and healthcare practices, plus an investment firm and other SMBs. We withhold the individual names and localities. Note the split: the operator is Russian-speaking; the targets are Spanish.
Per entity, the attacker pulled the complete Business Central tenant, and in several cases the document attachments too. The largest single victim alone accounts for 6.6 GB.
| Entity | Files | Exfiltrated | Data types |
|---|---|---|---|
| Entity A | 24 | 6.6 GB | customer database, document attachments, general ledger, inventory, purchase invoices |
| Entity B | 23 | 1.4 GB | credit memos, general ledger, inventory, purchase orders, sales invoices |
| Entity C | 91 | 912 MB | scanned documents |
| Entity D | 35 | 630 MB | scanned documents |
| Entity E | 17 | 487 MB | credit memos, purchase invoices, purchase orders, sales invoices |
| Entity F | 119 | 241 MB | scanned documents |
| Entity G | 10 | 232 MB | customer database, general ledger, inventory, purchase invoices, sales invoices |
| Entity H | 24 | 194 MB | scanned documents |
| Entity I | 7 | 181 MB | customer database, general ledger, inventory, purchase invoices, purchase orders |
| Entity J | 1 | 55 MB | sales invoices |
What this means
A full Business Central dump plus intrusion access is a total compromise of a small business:
- Personal-data breach (GDPR). Beyond the
customersdatabases, the corpus holds thousands of payment-card numbers, hundreds of IBANs and health records, reportable under Spanish and EU law and acutely sensitive for the dental/healthcare cluster. - Invoice and BEC fraud. Full sales and purchase invoices, orders and supplier details enable supplier impersonation and payment redirection.
- Extortion and financial exposure. The general ledger is every transaction, bank movement and balance, direct leverage and a complete map of the business.
- Onward access. Stolen Azure app secrets, private keys and tokens mean the exposure outlives any single password reset until every credential is rotated.
Attribution
Tooling, directory names and operator notes are in Russian; the recovered vocabulary is offensive-operations language:
| Captured term | Meaning |
|---|---|
| ВАЖНО | important |
| жертв | victims |
| пентест | pentest |
| уязвимост | vulnerability |
| фаззинг | fuzzing |
| эксплойт | exploit |
A working directory named project1488 also appears; 1488 is a numeric code associated with white-supremacist movements. We record it as an artifact of this operator's environment, not a confirmed group affiliation. Consistent with responsible practice, the Russian-language markers place a Russian-speaking operator or crew behind the infrastructure; language and borrowed-PoC artifacts are an attribution lead, not a link to a named group or state. The polyglot, AI-assembled toolkit is more consistent with an assembled crew than a single bespoke author.
Indicators of compromise
| Notable file | Size | SHA-256 |
|---|---|---|
| generalLedgerEntries.jsonl | 3.9 GB | 289df29fad549a46f7bc17cfb9b48cc1a188654b2c61faccd6b7a219a88d3ca2 |
| salesInvoices.jsonl | 1.2 GB | 399e2ad2f6c914b7cd4f269ba6272c0a9e05afb30ac962b90fa386d3b8b80b16 |
| OpenText_SAST_Fortify_Linux_26.1.0.tar.gz | 1.2 GB | 5ca72a168eda89ee7dc454af38bedb60295783f1e8ddb72cd050a9376a31399e |
| opencode.db | 772 MB | 323a7dee4e3d989877a9409e33fa7bae307569d77246f361b411fd7ea7605669 |
| Fortify_Tools_25.4.0_Linux.tar.gz | 547 MB | a0cbd1ae152d7f29cb87eda1e9be7d33603f08143cd801c1cea7f06a2798e5e8 |
| Metasploit Pro 5.0.0 -L0dxG.rar | 309 MB | 58f357a942081264a1f8959ef4a474fb1c1b25608decb9eb0efaf406b4fca83c |
| generalLedgerEntries.json | 249 MB | ceea53c431f97de6b6081c4a40ebb942bc333f86c0166d75779ce773ab00bc30 |
| generalLedgerEntries.jsonl | 222 MB | b41e49cbcab79c43720aaf79b2de3f9a8543f4c2618df435cd32fb01489cee98 |
MITRE ATT&CK
| Technique | Name | Observed via |
|---|---|---|
| T1595.002 | Vulnerability Scanning | nuclei (944-template library), dirsearch |
| T1552.001 | Credentials in Files | gitleaks over an exposed git repo → Azure app secret |
| T1078.004 | Valid Accounts: Cloud | stolen Azure service-principal, OAuth client-credentials |
| T1649 | Steal or Forge AD Certificates | certipy |
| T1003 / .001 / .006 | OS Credential Dumping (LSASS, DCSync) | mimikatz, secretsdump, dcsync |
| T1087.002 | Account Discovery: Domain | BloodHound, SharpHound, ldapsearch |
| T1021.002 | Remote Services: SMB | impacket psexec / wmiexec / smbexec / atexec |
| T1557.001 | LLMNR / NBT-NS Poisoning and Relay | responder, ntlmrelayx |
| T1071.001 | Web-protocol C2 | Sliver, Havoc, Cobalt Strike |
| T1572 | Protocol Tunneling | chisel, gost, ngrok |
| T1082 | System Information Discovery | winPEAS, linPEAS |
| T1496 | Resource Hijacking | xmrig (Monero miner) |
Mitigations
- Treat a leaked service-principal as a breach. Scan your own public and private repositories with
gitleaks; a single committed Azure client secret was the entire entry point here. Rotate and vault app secrets, and prefer workload-identity federation over long-lived secrets. - Lock down the Business Central API. Least-privilege API scopes, conditional access on the token endpoint, and alerting on client-credentials grants and bulk OData reads (
customers/generalLedgerEntriespulls) from unfamiliar IPs. - Patch the weaponised appliances now: SonicWall SMA1000 (CVE-2026-15409 / 15410), JetBrains TeamCity (CVE-2026-63077), BeyondTrust RS/PRA (CVE-2026-1731), KEMP LoadMaster (CVE-2026-8037), SmarterMail (CVE-2026-24423); rotate on-prem SharePoint machine keys.
- Break the AD chain: disable LLMNR/NBT-NS, enforce SMB signing (relay), monitor DCSync-style replication from non-DCs, and audit ADCS templates (certipy).
- Watch egress: Sliver/Havoc/Cobalt Strike beacons, chisel/gost/ngrok tunnels, and xmrig mining pools.
Summary
Operation Open Ledger is a compact illustration of where mid-tier intrusion has gone: a Russian-speaking operator, an AI agent, a folder of borrowed exploits, and a cloud API turned into a bulk-exfiltration tool against small businesses that will never see it in a log. They were undone by the oldest mistake, leaving their own server open, which is exactly how we find them. You can browse the running list of exposed C2 and malware infrastructure on live finds, see the IP profile for 89.124.67.72, or start free and hunt your own.
Hunt attacker infrastructure
Find exposed C2, open directories and loot servers from your own sensors, free.