๐จ CYBER INTELLIGENCE ALERT: ๐ช๐บ๐บ๐ฆ [UNCONFIRMED] MASSIVE WEBSHELL REPOSITORY CAMPAIGN BY THE EXPSX9 ACTOR ("X9 LIST")
[STATUS: UNCONFIRMED / PERIMETER COMPROMISE / WEBSHELL REPOSITORY / MULTI-SECTOR IMPACT]
A post attributed to the threat actor ExpSX9 has been detected on Telegram channels. The actor has published a list of targets across multiple sectors in Europe and Ukraine, suggesting the successful injection or upload of malicious WebShell scripts for remote command execution or subsequent resale of initial access.
Threat Actor: ExpSX9
Leakage Campaign: X9 List
Compromise Vector: Loading and Deployment of WebShells (PHP/ASPX).
๐ Breakdown of Compromised Infrastructures and Domains
Analysis of the sample reveals an indiscriminate selection of automated targets, ranging from local government portals to non-governmental organizations (NGOs) and universities:
๐ช๐ธ
catedrax.us.es (University of Seville - Spain): Institutional subdomain assigned to academic projects or chairs at the University of Seville. Hosting a WebShell here compromises the reputation of the educational domain (.es) and serves as a pivot point for academic malware campaigns.
๐ซ๐ท
curtafond-mairie.fr (Government Sector - France): Official portal of the Curtafond Town Hall (Mairie). The presence of access points on local government servers increases the risk of exfiltration of civil records or PII (Personally Identifiable Information) of citizens.
๐บ๐ฆ
caritas.if.ua (Humanitarian Sector / NGO - Ukraine): Website of the international charity Caritas in the Ivano-Frankivsk region. It represents a vulnerable target due to its handling of humanitarian aid and donor data.
๐จ๐ฟ
merkurpolice.cz /
carboservis.cz (Czech Republic): Czech commercial and industrial domains focused on corporate services.
๐ฎ๐น
cnesc.it /
cleanedizioni.it (Social and Publishing Sector - Italy): Portals linked to the National Civil Service Conference (CNESC) and publishing houses specializing in architecture and culture.
๐
crytek-hq.com /
childreninperaculture.com /
cuevasdelpino.com: Global entertainment platforms, permaculture educational organizations, and rural tourism sites.
โ ๏ธ Risk and Tactical Impact Considerations
Defacement and Malware Distribution: Web shells planted by ExpSX9 grant the attacker full control over web server file systems. This facilitates the modification of main pages (defacement), the hijacking of legitimate web traffic to redirect users to fake banking portals, or the injection of scripts for automated malware downloads (drive-by downloads).
Initial Access Brokerage (IAB): Ransomware syndicates commonly acquire these batches of basic web shells to use as initial entry points, escalating privileges within government or university internal networks to launch full-encryption attacks.
๐ก๏ธ Recommended Actions (Defensive Level)
Forensic Scanning of Public Directories: Prioritize notifying the IT teams of affected domains (with special emphasis on government and academic environments such as
us.es and
mairie.fr) to run perimeter scanning tools (e.g., YARA rules specific to web shells), locating scripts that have been modified or recently created in write-enabled folders like /uploads/, /images/, or /wp-content/.
HTTP Access Log Review: Analyze unusual POST requests directed at isolated files that show prolonged execution times or anomalous parameter passing (e.g., cmd=, exec=), and isolate the corresponding hosts. VECERT TOOLS
Strategic Monitoring Tools & Intelligence Platform:
๐
analyzer.vecert.io
Security Verification & Monitoring:
๐ก๏ธ
monitor.vecert.io
#CyberSecurity ๐
#ThreatIntelligence ๐
#WebShell #ExpSX9 #X9List #Spain ๐ช๐ธ
#France ๐ซ๐ท
#Ukraine ๐บ๐ฆ
#GovTech #EduTech #VECERT ๐ข