A device we operate, presenting as a Jenkins build server, was broken into twice through its unauthenticated Script Console. Both times the operator dropped a Mirai-derived DDoS bot that locks the machine down first: it kills SSH/Telnet, zeroes permissions on every download tool, poisons /etc/hosts against AV vendors, kills analysis tools on launch, and wipes the logs — so the box stops behaving like one you own before it ever floods a target. Full kill chain, IOCs, and defensive checks inside.
Over two days we watched a single operator chain two PAN-OS vulnerabilities in one request to install a custom-compiled, fully-obfuscated Sliver implant that appears in no public malware database and beacons to domains absent from every threat feed. A step-by-step walkthrough of the intrusion, with deployable Sigma and YARA detection.