Last seven days
- First activity
- Sep 2, 2026
- Last activity
- Sep 9, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 434 hostnames
C2 tracking
Derp observations, rolling seven-day window
Samples
70002422c17d8332ffe02ae9fb572dc984789e97083722d9ddb523820702b045 15b492a915af99ec266c5f0c92c7e696817697cbc166ab8e9213e887b2bf2317 42b6809b9f47a37d24d2d3b601195c121acd3b6f43f779c440fe7fb6c9ddeb73 e79a9f3378ec8193ceb93b54398b1ae9cc27172f857573eb2e383cc08e43a547 eb363a5f1485f4103b454262e63705e01fa67c96ab00f2e01e380a5324c74d07 eb433d94f5870ba52dc265159e6603297f32036757df7a2234494323acf5ed6a f6ac10489be16b1f62cb2d53e8d985d397383a0ffce1530173bf1e5137e71aaa 017d4c5c357492fefacd4963bfb44cba76b3403701bef201c1b31b45c4343deb 27194def5801b359dce33b326768373fa59318e7121db92f46b9c67847b0fcc1 650e7991aac038f2a06c003dbb9521e9aa58869490c61e8daa53b23f1dd182f2 MITRE ATT&CK
Reporting
Hunt.io identified an exposed staging server containing custom tooling, logs, and stolen data linked to intrusions at a Philippine nuclear-research agency and a defense-adjacent marine engineering company serving the Philippine Navy. The operator allegedly exploited ownCloud CVE-2023-49105 to forge pre-signed WebDAV URLs, impersonate users, and collect nuclear operations, personnel, strategic-planning, and credential data; available records indicate roughly 9 GB of data was exfiltrated. The naval contractorโs WordPress environment was separately compromised through LiteSpeed Cache CVE-2024-28000 and XML-RPC credential brute forcing, after which the actor staged a full website archive and database dump. Researchers assessed with medium confidence that the activity represented targeted collection aligned with Chinese interests amid South China Sea tensions, but did not attribute it to a named group. A separate EtherHiding/NoChain ClickFix infection was also found on the WordPress site, with no evidence tying it to the intrusion operator.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.