A series of DFIR case studies documented how attackers are increasingly relying on living-off-the-land techniques, uncommon runtimes, and legitimate administration tools to maintain access while evading detection. On Windows, investigators dissected a PHP backdoor that used php-win.exe, a scheduled task named ClockLauncher, and a ClockSystemService service to fetch and execute second-stage code invisibly; a separate intrusion used mailbombing and Microsoft Teams vishing to deliver a modular Deno-based RAT and proxy that persisted via the HKCU\Run key and communicated over WebSocket infrastructure hosted behind CloudFront. Another investigation traced a malicious .lnk file to a WebDAV-hosted Remcos payload cached under TfsStore\Tfs_DAV, while repeated compromises of a vulnerable Kentico CMS server led to webshell deployment, SEO spam, PowerShell-based payload retrieval, and installation of a malicious IIS module, HTTPCacheLog, that accepted commands through HTTP cookies.
On Linux and cloud infrastructure, researchers showed how attackers abused both commodity malware and stealthier post-exploitation tooling. TeamTNT-linked activity used tmate as a covert backdoor on Linux servers, often without normal login traces, while analysis of the REPTILE 2.0 rootkit loader showed it bypassing insmod by decrypting an embedded kernel module and loading it directly with the init_module syscall. A separate Sysrv botnet infection established cron persistence, masqueraded as kthreaddk, and included exploitation and brute-force features for propagation. In AWS, an extortion actor deleted S3 buckets and supplied a fake Linux “recovery” binary that merely simulated restoration rather than recovering cloud data. Across the investigations, defenders were urged to hunt for recurring artifacts such as scheduled tasks, Run keys, suspicious services, unusual binaries in user-writable paths, outbound SSH or WebSocket traffic, and syscall-level module loading, using telemetry and tools including Velociraptor, AutoRuns, Sysmon, and CloudTrail.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
30 events from the most recent confirmed update back to the earliest known activity.
Microsoft Defender telemetry recorded deno.exe creating a listening connection on 127.0.0.1:10022, corresponding to the malware's local TCP proxy and pivoting component.
On February 5, 2024, the attacker used the DeleteBucket API to erase all buckets after querying multiple S3 configuration settings such as versioning and object lock.
The purported Linux recovery binary supplied by the AWS extortionist was first uploaded to VirusTotal on February 2, 2024.
A second version of the AWS ransom note, without the recovery component, was first submitted to VirusTotal from France on January 29, 2024.
CloudTrail logs tied the start of the AWS extortion activity to reconnaissance on Amazon SES and S3 beginning on January 18, 2024.
The observation window for the govcert.ch malware-family analysis ran through December 2022, forming the basis for the article's eight recurring hunting artifacts.
The defensive analysis referenced in the article covers the top ten malware families observed in Switzerland by govcert.ch starting in April 2022, focusing on endpoint artifacts left by second-stage malware.
The article states that endpoint protection did not initially block the implant or its C2 traffic, and that detection happened later during reconnaissance involving LDAP queries and certificate-related activity.
The malware launched deno.exe via conhost.exe --headless, added a Deno_AutoRun value under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and maintained a WebSocket C2 connection to d2cff16eusb8mg.cloudfront[.]net.
One employee answered the vishing call and was convinced to download patch09913.b from a fake self-service portal, extract it into AppData\Roaming\DenoJSEnv, and execute the payload.
The Deno-based intrusion began with a high-volume mailbombing campaign against three employees, followed by Microsoft Teams calls from an external account impersonating internal IT support.
The author reported that at least one tested EDR did not generate an alert for the PHP backdoor execution chain or the Bluetrait agent installation.
In lab testing, the author used the PHP backdoor to silently download and install a Bluetrait agent via MSI, which checked in successfully within seconds.
Responders also found a Windows service named ClockSystemService configured to run as LocalSystem, providing an additional persistence mechanism for the PHP backdoor.
Investigation showed ClockLauncher launched php-win.exe from a temporary directory to run 5.php, a backdoor that polled a cutt.ly URL, decoded a second-stage URL from redirect headers, fetched remote PHP, and executed it with eval.
During an incident response engagement, investigators identified an unusual scheduled task named ClockLauncher in AutoRuns data from servers and workstations.
The REPTILE analysis cites Mandiant's observation that UNC3886 used a custom REPTILE launcher updated with a daemonization function.
During the follow-on Kentico investigation, responders discovered additional webshells on the server, including WebPartZone.ashx.
The downloaded dll.bat fetched HTTPCacheLog.dll from 216.83.45.170:90 and installed it as an IIS module named HTTPCacheLog, which hooked BeginRequest and accepted commands via HTTP cookies.
PowerShell and Sysmon logs showed w3wp.exe spawning cmd.exe and a base64-encoded PowerShell command as NT AUTHORITY\SYSTEM to download dll.bat from 216.83.45.170:90.
Five months after the first Kentico incident, the customer reported new issues on the same server and hosted websites, indicating the environment had been compromised again.
Analysis of schedule.lnk showed it would retrieve Erlianaw.exe from a remote WebDAV share, and the cached executable observed in TfsStore\Tfs_DAV matched a VirusTotal sample identified as Remcos.
An open directory at 216.9.224.58:5555 was found hosting malware-related files including a malicious shortcut named schedule.lnk.
Analysis of the 41hs1z sample identified it as part of the Sysrv botnet, with persistence via cron, randomized execution paths, and a config.json pointing to 194.38.23.2:8080.
A customer incident response case began when EDR detected a crypto miner on a Linux endpoint, leading to analysis of a malicious file named 41hs1z.
After the initial compromise, the customer added a rewrite rule to block .asmx access except from approved source ranges, but the mitigation was implemented only after attackers had already gained access.
Investigators found evidence including PrintNotifyPotato.exe, malicious rewrite rules, attacker-modified ASPX files, and SEO-spam behavior, and determined the server's Kentico CMS installation was vulnerable to remote code execution via /CMSPages/Staging/SyncServer.asmx.
The National Cybersecurity Center of Switzerland notified the customer that a domain in the customer's IP range was infected, adding evidence of compromise on the Kentico-hosting server.
A customer reported sporadic crashes of the IIS worker process w3wp.exe on a server hosting Kentico CMS sites, prompting forensic investigation.
A customer reported that an attacker had deleted several AWS S3 buckets, claimed to have downloaded data, and left a ransom note with a supposed recovery archive.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
dfir.ch
Open sourcedfir.ch
Open sourcedfir.ch
Open sourcedfir.ch
Open sourcedfir.ch
Open sourcedfir.ch
Open sourcedocs.velociraptor.app
Open sourcedocs.velociraptor.app
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.