Attackers breached systems supporting the 14th National Games of China before the event began, likely gaining code execution through a vulnerable web server component tied to route.lua or index.lua and an upload API. Investigators found the operators uploaded reverse shells and web shells, tested file-type restrictions by disguising payloads as images, and tried to reconfigure the server to execute .lua files. When one preferred Chinese web shell setup failed, they deployed a weaponized Tomcat instance configured with Rebeyond Behinder for persistence and remote control, alongside tools including fscan, dnscrypt-proxy, and an MSSQL command utility.
Separate technical analysis identified Behinder, also known as Ice Scorpion, as a publicly available multi-platform web shell used in major intrusions including SonicWall and ProxyShell-related compromises. The malware supports command execution, file management, persistence, in-memory web shell injection, and integration with frameworks such as Meterpreter and Cobalt Strike, while using encrypted HTTP POST traffic and a hardcoded communication key derived from the MD5 hash of rebeyond. Researchers also examined a modified variant, rebeyond-Mode, which adds decoy pages and command obfuscation while reusing Behinder payloads and the same hardcoded key, underscoring how adaptable the tool remains for post-exploitation operations.

Pull IOCs and campaign context straight into your stack.
9 events from the most recent confirmed update back to the earliest known activity.
The 14th National Games of China began in Shaanxi after the breach had apparently been successfully resolved before the event started.
Researchers concluded the attackers probably achieved initial code execution at around 10:00 AM local time by exploiting a web-server vulnerability, possibly involving route.lua or index.lua with an upload API.
Avast reported that attackers tested allowed file types and extensions on systems hosting content for the 14th National Games of China, repeatedly uploading the same benign image under different extensions to probe execution paths.
The article states that a Java error impacting Behinder's anti-detection-related functionality had been a known open issue since June 2021.
The Behinder web shell gained an in-memory web-shell injection feature called MemShell in an April 2021 update, expanding its persistence and post-exploitation capabilities.
The attackers placed tools including fscan, dnscrypt-proxy, mssql-command-tool, and Behinder on the compromised server, then used a Go-based exploitation framework and fscan to fingerprint services, brute-force credentials, and attempt lateral movement.
When their preferred Chinese web-shell setup did not work, the attackers uploaded and ran a Tomcat server configured with Rebeyond Behinder to maintain access and control.
The intruders uploaded a www.conf file disguised as a PNG in an effort to reconfigure the web server so that .lua files would execute, supporting their preferred shell deployment method.
After initial access, the attackers uploaded multiple reverse shells and web shells, including Lua and PHP payloads, and used proof-of-concept scripts to test what execution was possible on the target environment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.