← All campaigns

Tag

jenkins

2 campaigns

Compare these two campaigns →

The DDoS Zombie That Won't Let Go

A device we operate, presenting as a Jenkins build server, was broken into twice through its unauthenticated Script Console. Both times the operator dropped a Mirai-derived DDoS bot that locks the machine down first: it kills SSH/Telnet, zeroes permissions on every download tool, poisons /etc/hosts against AV vendors, kills analysis tools on launch, and wipes the logs — so the box stops behaving like one you own before it ever floods a target. Full kill chain, IOCs, and defensive checks inside.

2026-09-10

The Backdoor Key That Puts Itself Back

A threat actor breached a Jenkins server through its unauthenticated Script Console, then installed a self-healing SSH backdoor: delete the key and a systemd timer disguised as an update checker puts it back within five minutes. They stole the keys that decrypt the entire Jenkins credential store, harvested AWS credentials, and two days later deployed a cryptominer throttled to avoid detection. Full kill chain, IOCs, and Sigma detection rules inside.

2026-09-02