Home Cyber Security News New Cyber Espionage Campaign Targets Exchange & IIS with Custom Backdoors

New Cyber Espionage Campaign Targets Exchange & IIS with Custom Backdoors

0
Cyber Espionage Campaign
Cyber Espionage Campaign

A sophisticated cyber-espionage group known as xHunt has resurfaced with new intrusions targeting organizations in Kuwait’s shipping, transportation, and government sectors, continuing a campaign that began in 2018.

Researchers have linked this latest activity to ongoing operations that leverage Microsoft Exchange and IIS web servers, where attackers deploy a growing family of custom PowerShell-based backdoors.

The group, believed to conduct long-term intelligence collection, takes its name from the anime Hunter x Hunter, as many of its tools bear the names of characters such as HisokaSakabotaNetero, and Killua.

Earlier campaigns between 2019 and 2020 involved intrusions into Kuwaiti infrastructure, resulting in the discovery of several custom implants, including TriFive, Snugy (a CASHY200 variant), and the BumbleBee webshell.

Persistent Access via PowerShell and Mail Protocols

xHunt’s toolset demonstrates an advanced understanding of Windows internals and enterprise networks.

The TriFive and Snugy backdoors are written entirely in PowerShell, enabling stealthy execution via scheduled tasks that run every few minutes.

These scripts use execution policy bypasses to maintain persistence while remaining under endpoint detection thresholds.

One of xHunt’s most creative command-and-control mechanisms uses Exchange Web Services (EWS).

The TriFive backdoor interacts with a victim’s mailbox, sending and receiving encrypted PowerShell commands hidden in the Drafts or Deleted Items folders.

Each command is base64-encoded and obfuscated before execution, and the output is returned as another encoded draft, enabling covert communication through legitimate email traffic.

For lateral movement and internal access, xHunt has used SSH tunnels created with PuTTY’s Plink utility to connect to BumbleBee webshells on internal IIS instances.

In some intrusions, these tunnels targeted TCP ports 3389 and 80, giving attackers remote access to RDP services and internal web applications not exposed to the internet.

The group has also conducted watering-hole attacks, compromising a Kuwaiti government website and stealing credentials by embedding a hidden HTML request to an attacker-controlled SMB share.

When visitors’ browsers attempted authentication, their NTLMv2 hashes were silently captured and reused for subsequent authentication attempts.

Researchers have noted consistent defense-evasion behavior, including mimicking legitimate task names (e.g., “ResolutionHosts”) to obscure persistence mechanisms, modifying Windows registry keys to expose plaintext credentials in memory, and using VPN services to rotate IP addresses across European nodes, complicating attribution.

Security professionals are urged to test their environments against xHunt’s TTPs through active threat simulation.

Platforms like Picus Security Threat Library offer prebuilt scenarios that replicate xHunt’s tradecraft to help organizations measure and strengthen their defensive posture.

Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here