{"id":12579,"date":"2026-05-03T10:03:37","date_gmt":"2026-05-03T10:03:37","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/05\/03\/hackers-breach-government-and-military-servers-by-exploiting-cpanel-vulnerability\/"},"modified":"2026-05-03T10:03:37","modified_gmt":"2026-05-03T10:03:37","slug":"hackers-breach-government-and-military-servers-by-exploiting-cpanel-vulnerability","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/05\/03\/hackers-breach-government-and-military-servers-by-exploiting-cpanel-vulnerability\/","title":{"rendered":"Hackers Breach Government and Military Servers by Exploiting cPanel Vulnerability"},"content":{"rendered":"<p>    Hackers Breach Government and Military Servers by Exploiting cPanel Vulnerability<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated adversarial campaign targeting South-East Asian government and military infrastructure, combining rapid exploitation of a critical cPanel authentication bypass with a custom zero-day exploit chain against an Indonesian defense-sector portal and ultimately pivoting to exfiltrate over 4GB of sensitive Chinese railway documents.<\/p>\n<p>The campaign\u2019s initial access vector centered <a href=\"https:\/\/cybersecuritynews.com\/cpanel-authentication-flaw\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">on CVE-2026-41940<\/a>, a critical CVSS 9.8 authentication bypass in cPanel and WHM affecting all versions after v11.40.<\/p>\n<p>The flaw exploits CRLF injection in the login and session-loading processes, allowing an unauthenticated attacker to manipulate the <code>whostmgrsession<\/code> cookie and gain full root-level administrative access without valid credentials.<\/p>\n<p><a href=\"https:\/\/cybersecuritynews.com\/cpanel-0-day-authentication-bypass-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Exploitation was confirmed in the wild<\/a> before cPanel\u2019s patch was released on April 28, 2026, and CISA subsequently added it to its Known Exploited Vulnerabilities catalog. In this campaign, cPanel exploitation represented only one component of a broader and more alarming operation uncovered from an exposed <a href=\"https:\/\/cybersecuritynews.com\/command-and-controlc2-server\/\" target=\"_blank\" rel=\"noreferrer noopener\">command-and-control (C2) server<\/a>.<\/p>\n<h2 class=\"wp-block-heading\" id=\"novel-sqli-to-rce-exploit-against-indonesian-defen\"><strong>cPanel Vulnerability Exploited<\/strong><\/h2>\n<p>More significantly, Ctrl-Alt-Intel recovered a custom exploit targeting an Indonesian Defence sector training portal.<\/p>\n<p>The threat actor already possessed valid credentials and bypassed the portal\u2019s CAPTCHA mechanism by reading the expected CAPTCHA value directly from the server-issued session cookie, rendering the challenge completely ineffective without solving it.<\/p>\n<p>Once inside, the actor targeted a document-management function, injecting SQL into the document-name field via a vulnerable save endpoint.<\/p>\n<p>The SQL injection was then escalated to full operating system access by abusing PostgreSQL\u2019s <code>COPY ... TO PROGRAM<\/code> capability, which allows the database server to spawn arbitrary shell commands.<\/p>\n<p>Command output was captured to <code>\/tmp<\/code>, base64-encoded, and re-ingested into application records using <code>pg_read_file()<\/code> \u2014 a stealthy, file-read-based exfiltration channel entirely native to the database layer.<\/p>\n<p>The exploit script, named <code>exploit_siak_bahasa.py<\/code> (SHA-256: <code>974E272A...<\/code>), contained Vietnamese-language comments, though <a href=\"https:\/\/ctrlaltintel.com\/research\/SEA-CPanel\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Ctrl-Alt-Intel explicitly cautions<\/a> this is insufficient for attribution and may represent deliberate misdirection.<\/p>\n<p>For command and control, the actor <a href=\"https:\/\/cybersecuritynews.com\/adaptixc2-released\/\" target=\"_blank\" rel=\"noreferrer noopener\">deployed an AdaptixC2 payload<\/a> (ELF binary named <code>1<\/code>) configured to beacon to <code>delicate-dew.serveftp[.]com:4455<\/code>, with server-side telemetry corroborating the C2 address at <code>95.111.250[.]175<\/code>.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgAM4XwaZn51dGF0Qb8cbcrMFI8TGE5uiBcItwy8IqCwR7WzpT4nmhHpOfk0sCAn25KFcn29q04qrc9cDiAbEGsWGj4z30INH5mCqYo-jBDfLMufFOTwiSS8cKpJ1eyRK1jys_XF1iwhD-ZLX10fZpOZv7wm8_rkMa3YWM0AAQlafSL6OXq-UPTeRvhOzL7\/s16000\/adap%2520c2.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">C2 Server (Source:Ctrl-Alt-Intel) <\/figcaption><\/figure>\n<p>A PowerShell reverse shell (<code>init.ps1<\/code>) was also recovered, establishing a TCP connection back to the same IP on port 4444.<\/p>\n<p>To ensure durable, persistent access, the actor combined OpenVPN and Ligolo into a layered pivot stack. An OpenVPN server was deployed on <code>95.111.250[.]175:1194\/UDP<\/code> as early as April 8, 2026, routing through the <code>10.8.0.0\/24<\/code> client subnet.<\/p>\n<p>The Ligolo proxy agent was installed under a hidden directory <code>\/usr\/local\/bin\/.netmon\/<\/code>, masqueraded as a systemd service named <code>systemd-update.service<\/code>, and configured to restart automatically \u2014 providing persistent re-entry even after reboots.<\/p>\n<p>Routing through this pivot infrastructure, the actor reached an internal host at <code>10.16.13.88<\/code> and deployed <code>exfil_docs_v2.sh<\/code>, a custom SFTP-based exfiltration script.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj0-foGr67kHGnjD4NxdEvlVguMvQik-rxK00qQrxruvbSIYbKAvwtSxCQm0GBoYCjbaQPxTLwL1SD4jBDSbzhWFU8cfBJF9g21cNt2jwSPyzLya0vzh9yYFxxqLojyRWjBQL6kFXVa_BhcfldQMlf6japGz1AFw5ap8sXXcgkYGA09vslBVBrybB8mDiZ9\/s16000\/Data%2520Exfil.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Data Exfiltration (Source:Ctrl-Alt-Intel) <\/figcaption><\/figure>\n<p>In total, 110 files (~4.37GB) were stolen from the China Railway Society Electrification Committee spanning <code>.pptx<\/code>, <code>.pdf<\/code>, <code>.docx<\/code>, and <code>.xlsx<\/code> formats dating from 2020 to 2024.<\/p>\n<p>Among the most sensitive materials were 2021 financial workbooks containing full names, PRC national ID numbers, bank account details, and phone numbers.<\/p>\n<p>Ctrl-Alt-Intel stops short of firm attribution, though the victimology South-East Asian military and government targets combined with theft of Chinese state-adjacent transport-sector data points to a deliberate regional intelligence collection effort.<\/p>\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/cpanelsniper-poc-exploit\/\" target=\"_blank\" rel=\"noreferrer noopener\">Shadowserver Foundation confirmed<\/a> on April 30, 2026, that 44,000 unique IP addresses were observed scanning for victims, launching exploits, or conducting brute-force attacks against their honeypot sensors.<\/p>\n<p>Organizations running cPanel\/WHM are urged to patch to the latest version immediately and audit server logs for signs of CRLF-based session manipulation.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-indicators-of-compromise-iocs\"><strong>Indicators of Compromise (IoCs)<\/strong><\/h2>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Indicator<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Type<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Context<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>95.111.250[.]175<\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">IP Address<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Primary attacker VPS; OpenVPN, reverse shell, and pivot infrastructure<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>delicate-dew.serveftp[.]com<\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Domain<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Domain associated with the same infrastructure; present in recovered certificate material<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>systemd-update.service<\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">File Name<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Masqueraded Linux persistence service<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>\/usr\/local\/bin\/.netmon\/systemd-helper<\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">File Path<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Hidden Linux reverse-connect payload path<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>init.ps1<\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">File Name<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">PowerShell reverse shell payload<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>64674342041873DBB18B1DD9BB1CA391AF85B5E755DEFFB4C1612EF668349325<\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">SHA-256<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Hash of <code>init.ps1<\/code>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>exploit_siak_bahasa.py<\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">File Name<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Custom authenticated SQLi \u2192 PostgreSQL RCE exploit<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>974E272AD1DC7D5AADC3C7A48EC00EB201D04BA59EC5B0B17C2F8E9CD2F9C9CD<\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">SHA-256<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Hash of <code>exploit_siak_bahasa.py<\/code>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>exfil_docs_v2.sh<\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">File Name<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Custom SFTP \/ lftp document exfiltration script<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>734F0D04DC2683E19E629B8EC7F55349B5BCFF4EB4F2F36F6ADBBDE1C023A24F<\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">SHA-256<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Hash of <code>exfil_docs_v2.sh<\/code>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>1<\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">File Name<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Linux ELF reverse-connect \/ pivot payload recovered alongside the custom exploit chain<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\"><code>1CFEADF01D24182362887B7C5F683E8BDB0E84CDDCE03E3B7564B2D9AB5D15CF<\/code><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">SHA-256<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Hash of ELF payload <code>1<\/code>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p><strong>Note:<\/strong>\u00a0<em>IP addresses and domains are intentionally defanged (e.g.,\u00a0<code>[.]<\/code>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM<\/em>.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cpanel-vulnerability-exploited\/\">Hackers Breach Government and Military Servers by Exploiting cPanel Vulnerability<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cpanel-vulnerability-exploited\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Breach Government and Military Servers by Exploiting cPanel Vulnerability A sophisticated adversarial campaign targeting South-East Asian government and military infrastructure, combining rapid exploitation of a critical cPanel authentication bypass with a custom zero-day exploit chain against an Indonesian defense-sector portal and ultimately pivoting to exfiltrate over 4GB of sensitive Chinese railway documents. The campaign\u2019s [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1636,129,63],"tags":[130],"class_list":["post-12579","post","type-post","status-publish","format-standard","hentry","category-cyber-attack-news","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12579"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12579"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12579\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12579"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12579"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12579"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}