{"slug": "an-ai-assembled-crew-exfiltrating-erp-data-from-spanish-smbs", "title": "An AI-assembled crew exfiltrating ERP data from Spanish SMBs", "summary": "An intrusion crew exposed its own working environment on the open directory 89.124.67.72 at SERVERS TECH FZCO (AS216071) in the Netherlands, and huntback recovered 10,428 files including a custom Microsoft Dynamics 365 Business Central exfiltration pipeline, a six-product enterprise exploit kit, and 15 GB of data stolen from 10 Spanish small businesses. The crew stole an Azure service-principal secret from a victim's exposed git repository using gitleaks, minted OAuth tokens, and bulk-dumped ERP tenants through the Business Central REST API with a pipeline versioned to v2.0.2, while the operator drove the work through an opencode AI agent. The corpus, whose sensor history places the host between 2026-09-28 and 2026-10-01, also contained a full Active Directory arsenal of 24 tools, Sliver, Havoc and Cobalt Strike C2, and an xmrig Monero miner.", "body_md": "# Operation Open Ledger: an AI-assembled crew exfiltrating ERP data from Spanish SMBs\n\nOpen directories are where attackers leak too. On `89.124.67.72` an intrusion crew left its entire working environment exposed to the internet, and we recovered **10,428 files**: the operator's shell history, a custom Microsoft Dynamics 365 Business Central exfiltration pipeline, a six-product enterprise exploit kit, a full Active Directory arsenal, a Sliver C2, a Monero miner, and **15 GB of data stolen from a cluster of Spanish small businesses**. The tradecraft is Russian-speaking and visibly AI-assisted. This report is built from that corpus.\n\n**Handling note.** Victim organisations are anonymised to entity types; specific names and localities are withheld. Live credentials recovered in the corpus (an Azure app secret, private keys, API tokens) and personal data (payment-card numbers, IBANs, health records) are redacted throughout and are not reproduced here. Exploit techniques are described for defenders; working payloads are not republished.\n\n## Key findings\n\n- **One exposed server, the whole operation.** 10,428 files across the crew's working tree, shell history included, recovered from an open directory the operator exposed themselves.\n- **Cloud-API exfiltration, not malware.** The crew stole an**Azure service-principal secret** from a victim's exposed git repository (via`gitleaks` ), minted OAuth tokens, and bulk-dumped every tenant through the**Business Central REST API** with a purpose-built pipeline (`bc_full_dump.py` /`bc_export.sh` , versioned to v2.0.2, with run logs).\n- **A six-product exploit kit.** Custom modules for SonicWall SMA1000 (CVE-2026-15409/15410, CVSS 10), JetBrains TeamCity (CVE-2026-63077), BeyondTrust (CVE-2026-1731), KEMP LoadMaster (CVE-2026-8037), SmarterMail (CVE-2026-24423) and an on-prem SharePoint key-dump.\n- **Full Active Directory arsenal.** 24 tools including mimikatz, secretsdump, DCSync, BloodHound, impacket, responder, ntlmrelayx and certipy, plus Sliver, Havoc and Cobalt Strike C2, chisel/gost/ngrok tunneling, and an**xmrig** Monero miner.\n- **Assembled, not authored, and AI-assisted.** The operator drives the work through an**opencode** AI agent; the borrowed PoCs are a polyglot of English, Russian and Chinese, one README credits ChatGPT. Running these tools establishes use, not authorship.\n- **Data at scale.** 15 GB from 10 Spanish SMBs: full ERP tenants plus payment-card numbers, IBANs and health records.\n\n## Discovery\n\nhuntback indexes malicious open directories across high-risk hosting and bulletproof ASN space, and correlates them with attacker activity on our deception network. This host, `89.124.67.72` at SERVERS TECH FZCO (AS216071) in The Netherlands, surfaced as an open HTTP directory and was promoted to a full harvest because its listing scored unambiguously malicious: offensive tooling, an `exploit`-labelled payload and a Sliver artifact next to bulk ERP exports is not something a legitimate server exposes. We recovered 10,428 files and classified the contents automatically, extracting secrets, victim identifiers, tooling and language markers into the dossier this report is built from. Our sensor history places the host between 2026-09-28 and 2026-10-01.\n\n## Attack chain\n\nTwo paths run from the same working directory. A **cloud path** turns stolen credentials into a clean API dump of each victim's ERP; an **intrusion path** exploits exposed enterprise appliances and pivots through Active Directory. Both feed the same loot tree, sorted one folder per victim.\n\n**OSINT & recon**\n\n**Secret theft (gitleaks)**\n\n**BC API token mint**\n\n**ERP bulk exfil**\n\n**Appliance exploit + AD pivot**\n\n**C2, mining, loot sort**\n\nThe operator's shell history shows the sequence directly: `dirsearch` sweeps of a target dental company's subdomains, then a working folder `/opt/pentest/findings/spain-dental-osint/` holding `02-infra-map.md`, a `gitleaks-report.json` over a recovered git repository, and a finding file literally named `03-CRITICAL-azure-bc-creds.md`.\n\n## The exfiltration pipeline\n\nThe theft needs no malware on the victim. From the leaked git repository the crew recovered an Azure Entra ID application's client credentials, then ran the standard OAuth *client-credentials* grant to mint tokens and read the Business Central REST API directly, exactly as a legitimate integration would. The commands are preserved verbatim in the shell history (secrets and tenant redacted):\n\nAround that core sits a real engineering effort: `bc_full_dump.py` and `bc_export.sh` (kept in versioned backups up to `v2.0.2`, plus a `bc_export_windowed.sh` variant), an `export` step that lands the data as JSON/JSONL, and a stack of run logs (`bc_full_dump_run1-3.log`, `bc_export_run.log`) recording the pulls. A single `generalLedgerEntries` export reached 3.9 GB. This is the whole financial system of each business: customers, ledgers, invoices and attachments, not a sample.\n\n## The exploit arsenal\n\nParallel to the cloud theft, the crew carries a bundle of ready exploits for internet-facing enterprise appliances, each with its own README, and most tagged with a 2026 CVE on, or heading for, CISA's KEV list:\n\n| Product | CVE | Technique | Notes | \n|---|---|---|---|\n| **SonicWall SMA1000** | CVE-2026-15409 + CVE-2026-15410 | SSRF → Erlang RCE → root privesc | CVSS 10.0, CISA KEV | \n| **JetBrains TeamCity** | CVE-2026-63077 | Unauthenticated RCE (XStream deserialization) | public Rapid7 PoC | \n| **BeyondTrust RS / PRA** | CVE-2026-1731 | Pre-auth RCE (WebSocket argument injection) | variant of CVE-2024-12356 | \n| **Progress KEMP LoadMaster** | CVE-2026-8037 | Unauthenticated command injection | Chinese-language PoC + nuclei template | \n| **SmarterMail** | CVE-2026-24423 | Unauth SSRF → RCE (ConnectToHub) | PoC credited to ChatGPT | \n| **Microsoft SharePoint (on-prem)** | key-dump module | Machine-key theft (ToolShell-class) | PowerShell | \n\nThe quality and provenance vary tellingly. The SonicWall module is a polished SSRF-to-root chain (tunnel through `wsproxy` into the appliance's internal Erlang distribution service, authenticate with a hardcoded cookie, execute via `os:cmd`, then escalate through an AMC path traversal). The TeamCity exploit is lifted from a public Rapid7 proof-of-concept. The KEMP and SmarterMail modules carry Chinese-language READMEs, and the SmarterMail one credits its authorship to ChatGPT. This is a kit assembled from many hands, not one author's work.\n\n## AI-assembled tradecraft\n\nThe shell history opens with the operator installing the **opencode** AI coding agent (`curl -fsSL https://opencode.ai/install | bash`), authenticating it and wiring up its config, and the 772 MB `opencode.db` sits in the loot. The crew drives reconnaissance, code and exploitation through that agent, and the borrowed PoCs, English, Russian and Chinese, one explicitly \"made by ChatGPT\", show the same pattern: large-language-model assembly of public offensive code into a working pipeline. Alongside it we recovered licensed OpenText / Fortify SAST and Metasploit Pro, nuclei (a 944-template scanning library), and katana. It is a commercial-grade, AI-accelerated operation, not a commodity botnet.\n\n## Post-exploitation toolkit\n\nOnce inside, the crew's kit is a textbook Active Directory chain: **responder** and **ntlmrelayx** for LLMNR/NBT-NS poisoning and relay; **mimikatz**, **secretsdump** and **DCSync** for credential theft; **BloodHound** / **SharpHound** and **ldapsearch** for mapping; **impacket** (`psexec`, `wmiexec`, `smbexec`, `atexec`) for lateral movement; **certipy** for ADCS certificate abuse; and **winPEAS** / **linPEAS** for privilege escalation. For command and control and egress we found **Sliver** (with a C2 config), **Havoc** and **Cobalt Strike**, tunnelled over **chisel**, **gost** and **ngrok**. And purely for profit, an **xmrig** Monero miner. Recovered secrets include 15 private keys, 10 Azure secrets, AWS and GCP keys, a GitHub token and JWTs.\n\n## A note on CVE scope\n\nThe operator's nuclei library references **944 distinct CVEs**, most dating back as far as 2000. That number is the breadth of their *scanning* templates, not their kill list. The CVEs they actually weaponised with bespoke modules are the six in the table above. We separate the two deliberately: carrying a template is not exploiting a flaw, and conflating the scan library with confirmed exploitation would badly overstate the campaign. Where a README's CVE label is a variant or inherited identifier (BeyondTrust's CVE-2026-1731 is a sibling of CVE-2024-12356), we say so rather than taking the label at face value.\n\n## Who the victims are\n\nThe operator sorted exfiltration into one folder per victim, 10 distinct organisations, and the corpus tells us the *type* of entities involved without our needing to name them. The working directory is literally named `spain-dental-osint`; filenames and documents reference the Spanish commercial registry, regional towns, the national postal service and Spanish-language accounting terms, alongside `S.L.` (*Sociedad Limitada*) suffixes. The victims are **Spanish small and mid-sized businesses**, skewed toward **dental and healthcare practices**, plus an investment firm and other SMBs. We withhold the individual names and localities. Note the split: the operator is Russian-speaking; the targets are Spanish.\n\nPer entity, the attacker pulled the complete Business Central tenant, and in several cases the document attachments too. The largest single victim alone accounts for 6.6 GB.\n\n| Entity | Files | Exfiltrated | Data types | \n|---|---|---|---|\n| **Entity A** | 24 | 6.6 GB | customer database, document attachments, general ledger, inventory, purchase invoices | \n| **Entity B** | 23 | 1.4 GB | credit memos, general ledger, inventory, purchase orders, sales invoices | \n| **Entity C** | 91 | 912 MB | scanned documents | \n| **Entity D** | 35 | 630 MB | scanned documents | \n| **Entity E** | 17 | 487 MB | credit memos, purchase invoices, purchase orders, sales invoices | \n| **Entity F** | 119 | 241 MB | scanned documents | \n| **Entity G** | 10 | 232 MB | customer database, general ledger, inventory, purchase invoices, sales invoices | \n| **Entity H** | 24 | 194 MB | scanned documents | \n| **Entity I** | 7 | 181 MB | customer database, general ledger, inventory, purchase invoices, purchase orders | \n| **Entity J** | 1 | 55 MB | sales invoices | \n\n## What this means\n\nA full Business Central dump plus intrusion access is a total compromise of a small business:\n\n- **Personal-data breach (GDPR).** Beyond the`customers` databases, the corpus holds**thousands of payment-card numbers, hundreds of IBANs and health records** , reportable under Spanish and EU law and acutely sensitive for the dental/healthcare cluster.\n- **Invoice and BEC fraud.** Full sales and purchase invoices, orders and supplier details enable supplier impersonation and payment redirection.\n- **Extortion and financial exposure.** The general ledger is every transaction, bank movement and balance, direct leverage and a complete map of the business.\n- **Onward access.** Stolen Azure app secrets, private keys and tokens mean the exposure outlives any single password reset until every credential is rotated.\n\n## Attribution\n\nTooling, directory names and operator notes are in Russian; the recovered vocabulary is offensive-operations language:\n\n| Captured term | Meaning | \n|---|---|\n| ВАЖНО | important | \n| жертв | victims | \n| пентест | pentest | \n| уязвимост | vulnerability | \n| фаззинг | fuzzing | \n| эксплойт | exploit | \n\nA working directory named `project1488` also appears; 1488 is a numeric code associated with white-supremacist movements. We record it as an artifact of this operator's environment, not a confirmed group affiliation. Consistent with responsible practice, the Russian-language markers place a Russian-speaking operator or crew behind the infrastructure; language and borrowed-PoC artifacts are an attribution *lead*, not a link to a named group or state. The polyglot, AI-assembled toolkit is more consistent with an assembled crew than a single bespoke author.\n\n## Indicators of compromise\n\n| Notable file | Size | SHA-256 | \n|---|---|---|\n| generalLedgerEntries.jsonl | 3.9 GB | 289df29fad549a46f7bc17cfb9b48cc1a188654b2c61faccd6b7a219a88d3ca2 | \n| salesInvoices.jsonl | 1.2 GB | 399e2ad2f6c914b7cd4f269ba6272c0a9e05afb30ac962b90fa386d3b8b80b16 | \n| OpenText_SAST_Fortify_Linux_26.1.0.tar.gz | 1.2 GB | 5ca72a168eda89ee7dc454af38bedb60295783f1e8ddb72cd050a9376a31399e | \n| opencode.db | 772 MB | 323a7dee4e3d989877a9409e33fa7bae307569d77246f361b411fd7ea7605669 | \n| Fortify_Tools_25.4.0_Linux.tar.gz | 547 MB | a0cbd1ae152d7f29cb87eda1e9be7d33603f08143cd801c1cea7f06a2798e5e8 | \n| Metasploit Pro 5.0.0 -L0dxG.rar | 309 MB | 58f357a942081264a1f8959ef4a474fb1c1b25608decb9eb0efaf406b4fca83c | \n| generalLedgerEntries.json | 249 MB | ceea53c431f97de6b6081c4a40ebb942bc333f86c0166d75779ce773ab00bc30 | \n| generalLedgerEntries.jsonl | 222 MB | b41e49cbcab79c43720aaf79b2de3f9a8543f4c2618df435cd32fb01489cee98 | \n\n## MITRE ATT&CK\n\n| Technique | Name | Observed via | \n|---|---|---|\n| T1595.002 | Vulnerability Scanning | nuclei (944-template library), dirsearch | \n| T1552.001 | Credentials in Files | gitleaks over an exposed git repo → Azure app secret | \n| T1078.004 | Valid Accounts: Cloud | stolen Azure service-principal, OAuth client-credentials | \n| T1649 | Steal or Forge AD Certificates | certipy | \n| T1003 / .001 / .006 | OS Credential Dumping (LSASS, DCSync) | mimikatz, secretsdump, dcsync | \n| T1087.002 | Account Discovery: Domain | BloodHound, SharpHound, ldapsearch | \n| T1021.002 | Remote Services: SMB | impacket psexec / wmiexec / smbexec / atexec | \n| T1557.001 | LLMNR / NBT-NS Poisoning and Relay | responder, ntlmrelayx | \n| T1071.001 | Web-protocol C2 | Sliver, Havoc, Cobalt Strike | \n| T1572 | Protocol Tunneling | chisel, gost, ngrok | \n| T1082 | System Information Discovery | winPEAS, linPEAS | \n| T1496 | Resource Hijacking | xmrig (Monero miner) | \n\n## Mitigations\n\n- **Treat a leaked service-principal as a breach.** Scan your own public and private repositories with`gitleaks` ; a single committed Azure client secret was the entire entry point here. Rotate and vault app secrets, and prefer workload-identity federation over long-lived secrets.\n- **Lock down the Business Central API.** Least-privilege API scopes, conditional access on the token endpoint, and alerting on client-credentials grants and bulk OData reads (`customers` /`generalLedgerEntries` pulls) from unfamiliar IPs.\n- **Patch the weaponised appliances now:** SonicWall SMA1000 (CVE-2026-15409 / 15410), JetBrains TeamCity (CVE-2026-63077), BeyondTrust RS/PRA (CVE-2026-1731), KEMP LoadMaster (CVE-2026-8037), SmarterMail (CVE-2026-24423); rotate on-prem SharePoint machine keys.\n- **Break the AD chain:** disable LLMNR/NBT-NS, enforce SMB signing (relay), monitor DCSync-style replication from non-DCs, and audit ADCS templates (certipy).\n- **Watch egress:** Sliver/Havoc/Cobalt Strike beacons, chisel/gost/ngrok tunnels, and xmrig mining pools.\n\n## Summary\n\nOperation Open Ledger is a compact illustration of where mid-tier intrusion has gone: a Russian-speaking operator, an AI agent, a folder of borrowed exploits, and a cloud API turned into a bulk-exfiltration tool against small businesses that will never see it in a log. They were undone by the oldest mistake, leaving their own server open, which is exactly how we find them. You can browse the running list of exposed C2 and malware infrastructure on [live finds](https://huntback.io/finds), see the [IP profile for 89.124.67.72](https://huntback.io/ip/89.124.67.72), or [start free](https://app.huntback.io/signup) and hunt your own.\n\n## Hunt attacker infrastructure\n\nFind exposed C2, open directories and loot servers from your own sensors, free.", "url": "https://wpnews.pro/news/an-ai-assembled-crew-exfiltrating-erp-data-from-spanish-smbs", "canonical_source": "https://huntback.io/blog/ai-crew-open-server-erp-exfil-spanish-smbs", "published_at": "2026-10-02 11:36:34+00:00", "updated_at": "2026-10-02 12:06:49.459322+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "artificial-intelligence"], "entities": ["huntback", "Microsoft Dynamics 365 Business Central", "SERVERS TECH FZCO", "SonicWall SMA1000", "JetBrains TeamCity", "BeyondTrust", "KEMP LoadMaster", "SmarterMail"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/an-ai-assembled-crew-exfiltrating-erp-data-from-spanish-smbs", "markdown": "https://wpnews.pro/news/an-ai-assembled-crew-exfiltrating-erp-data-from-spanish-smbs.md", "text": "https://wpnews.pro/news/an-ai-assembled-crew-exfiltrating-erp-data-from-spanish-smbs.txt", "jsonld": "https://wpnews.pro/news/an-ai-assembled-crew-exfiltrating-erp-data-from-spanish-smbs.jsonld"}}