← All campaigns

Objective

credential harvesting (Jenkins secrets, cloud credentials, SSH keys), banked for later use or resale rather than used immediately, plus opportunistic cryptomining once the initial access is established

1 campaign

One profiled campaign here — comparison opens up once a second one shares this objective.

The Backdoor Key That Puts Itself Back

A threat actor breached a Jenkins server through its unauthenticated Script Console, then installed a self-healing SSH backdoor: delete the key and a systemd timer disguised as an update checker puts it back within five minutes. They stole the keys that decrypt the entire Jenkins credential store, harvested AWS credentials, and two days later deployed a cryptominer throttled to avoid detection. Full kill chain, IOCs, and Sigma detection rules inside.

2026-09-02