Security1 publisher2 min readPublished
Attacker turned member-file uploads into webshells across a shared recreation platform
Huntress says a threat actor turned member-account file uploads into webshells on three web servers of a shared recreation-management platform. The same upload path served every tenant, and the attacker returned after one server was cleaned but not locked down.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The attacker first spent about six hours firing one unauthenticated technique after another at the first server, probably with AI-generated scripts, and none of it worked.
- The failed attempts included brute-forcing two login pages, IIS 8.3 tilde enumeration, WebDAV write verbs, upload-handler parser bypasses, and forced browsing.
- Fourteen files landed in the member upload directory in .aspx, .jpg and .pdf formats, with the images and PDFs used to test which extensions the server would execute.
- On every server, the shells planted disguised copies of themselves wherever matching folders already existed.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- capability Any user able to register on an affected tenant can attempt the same code execution, because the working path used the signup form and needed no exploit.
- exposure The webshells hunted for cardholder data on the payment tenant, so that tenant's customer card data is inside the breach, not just booking records.
- decision Deleting the shells does not end it; unless the upload handler stops executing member files and the attacker's accounts are revoked, a cleaned server stays open.
- constraint Detection tuned to the noisy unauthenticated probes would miss the entry, since the step that worked was an authenticated member upload.
Six hours of exotic probing bought the attacker nothing on the first server. The brute force against both login pages returned HTTP 200 and bounced back to the form rather than 302 to a logged-in page [8]. The IIS 8.3 tilde run crafted requests like a*~1* to list hidden files and failed [9]. Of eight WebDAV verbs tried, only OPTIONS answered, and it returned nothing but the methods the server allowed [10]. Edits to the upload scripts, ::$DATA appended to filenames and case-flipped names meant to slip past string filters all failed too [11].
Then the attacker used the feature. Of the 14 files uploaded, eight were .aspx and the other six split evenly between .jpg and .pdf [1]. Only the .aspx shells ran [13]. They executed ordinary recon commands such as whoami, hostname, dir D:\ /b and set, listed the IIS sites, and reached for the IIS worker process hosts file [14][15][18].
Huntress dates the activity to September 10, 2026 [1]. The platform is shared: one upload path served multiple tenants, so the same method carried across three web servers [3]. The repeatable step was mundane, a registration form and an upload handler that wrote member files to a directory the application would execute [2].
The actor adapted across the three compromises, getting quieter and adding anti-forensics as it went [17].
What to watch
- Whether Huntress or the vendor identifies the recreation-management platform and how many tenants were hit.
- Whether the payment tenant's processor confirms cardholder data was exfiltrated, not just searched.
- Whether the vendor ships an upload-handler fix that stops .aspx execution from member directories.