A threat actor repeatedly exploited or attempted to exploit a vulnerable Adobe ColdFusion server, then used IIS worker process w3wp.exe to run reconnaissance and deploy multiple steganographic webshells, including UA4fp7R.aspx and WRBYTR5750images.aspx. Huntress reported the intruder embedded the marker ONEPIECE in shell logic and maintained persistence across repeated restoration attempts, indicating the server was returned to production before remediation was complete.
The intrusion escalated into broad defense impairment designed to preserve access and obstruct responders. The actor timestomped files, disabled IIS logging and Microsoft Defender, killed security and logging tools, removed the ModSecurity IIS module, and used Image File Execution Options debugger registry entries to neutralize Sysmon and Filebeat. The attacker also weakened credential protections by enabling WDigest UseLogonCredential, exported ODBC registry data, and used Mimikatz-style credential dumping to write passwords and hashes to files before Huntress disrupted the operation prior to data theft or ransomware deployment.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Huntress reported that its SOC ultimately disrupted the intrusion before data exfiltration or ransomware encryption occurred. The incident was later described publicly in Huntress's June 29, 2026 blog post.
The threat actor exported ODBC registry data, enabled WDigest UseLogonCredential, and used tools associated with Mimikatz-style credential dumping to write passwords and hashes to files. These actions were part of the broader post-compromise activity on the server.
After the server was prematurely returned to service twice, the attacker intensified activity to preserve access and hinder investigation. Actions included timestomping files, disabling IIS logging and Microsoft Defender, killing logging and security tools, uninstalling the ModSecurity IIS module, and using IFEO registry debugger entries against Sysmon and Filebeat.
During the intrusion, the actor uploaded multiple webshells including UA4fp7R.aspx and WRBYTR5750images.aspx. Huntress said the shell logic contained the string ONEPIECE as an operational marker.
In June 2024, a threat actor repeatedly exploited or attempted to exploit a vulnerable Adobe ColdFusion server during a web server intrusion. The attacker used the IIS worker process w3wp.exe to launch reconnaissance commands after gaining access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.