Sunday, March 9, 2025
HomeCyber AttackIcePeony Hackers Exploiting Public Web Servers To Inject Webshells

IcePeony Hackers Exploiting Public Web Servers To Inject Webshells

Published on

SIEM as a Service

Follow Us on Google News

IcePeony, a China-nexus APT group, has been active since 2023, targeting India, Mauritius, and Vietnam by exploiting SQL injection vulnerabilities to compromise systems using webshells and backdoors, leveraging a custom IIS malware called IceCache.

The attackers accidentally exposed a server containing sensitive data, including a zsh_history file that revealed their detailed attack timeline and techniques.

They used aliases to simplify commands and access help information, such as “hPass” to access Mimikatz tutorials.

trial-and-error process
trial-and-error process

They used SQL injection and IceCache, compromised government websites, installed webshells, and exfiltrated sensitive domain user information.

They also employed tools like StaX, Diamorphine, craXcel, and WmiExec to expand their attack surface and maintain persistence.

Join ANY.RUN's FREE webinar on How to Improve Threat Investigations on Oct 23 - Register Here 

IcePeony’s StaX tool is a customized version of Stowaway. This high-performance proxy tool encrypts communication targets using Custom Base64 and AES for active mode, providing enhanced security for network traffic.

custom processing
custom processing

An attacker leveraged ProxyChains to execute malicious scripts “info.sh” and “linux_back.sh” on victim machines, which harvested system information, established persistence, and deployed a rootkit named Diamorphine. 

The IcePeony server hosted IceCache, malware targeting IIS servers used to attack the attack surface server. The related malware IceEvent, though not found in any logs, was likely used to compromise an offline computer.

IceCache details
IceCache details

IceCache, a Go-based ELF64 binary, is a malicious tool designed for intrusion operations. It is installed on IIS servers and offers various functionalities, such as command execution, file transfer, and proxy services. 

The malware’s developers have been actively improving its capabilities over time, as evidenced by the increasing number of commands and the evolution of its functionality.

IceEvent, a simple passive-mode backdoor, was discovered in India. It is installed as a service and executes commands through sockets and files. 

example of decoding the data during command execution
example of decoding the data during command execution

A and B were identified, with A focusing on reading files and executing processes and B on uploading and downloading files. All submissions were from India, highlighting the potential for domestic cyber threats.

The analysis by Nao_Sec reveals that IceEvent and IceCache share similar code, XOR keys, and command execution processes, suggesting a common developer and source code.

The malware’s communication data is easily decodable due to its reliance solely on XOR encryption.

Similarities
Similarities

The investigation revealed that IcePeony likely operates under a 996 working-hour system in the UTC+8 time zone.

Their consistent activity patterns, including extended workdays and limited weekends, suggest organized, professional operations rather than personal activities.

While code comments, malware origin, target selection, and infrastructure suggest IcePeony is a Chinese threat actor group likely state-sponsored, targeting governments and educational sectors in India, Mauritius, and Vietnam. 

IcePeony, a new Chinese cyber threat group, has been targeting Indian government websites since 2023. It uses SQL injection attacks to install web shells and steal credentials.

How to Choose an ultimate Managed SIEM solution for Your Security Team -> Download Free Guide (PDF)

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

10 Best Penetration Testing Companies in 2025

Penetration testing companies play a vital role in strengthening the cybersecurity defenses of organizations...

Lumma Stealer Using Fake Google Meet & Windows Update Sites to Launch “Click Fix” Style Attack

Cybersecurity researchers continue to track sophisticated "Click Fix" style distribution campaigns that deliver the...

Fake BianLian Ransom Demands Sent via Physical Letters to U.S. Firms

In a novel and concerning development, multiple U.S. organizations have reported receiving suspicious physical...

Strela Stealer Malware Attack Microsoft Outlook Users for Credential Theft

The cybersecurity landscape has recently been impacted by the emergence of the Strela Stealer...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

10 Best Penetration Testing Companies in 2025

Penetration testing companies play a vital role in strengthening the cybersecurity defenses of organizations...

Lumma Stealer Using Fake Google Meet & Windows Update Sites to Launch “Click Fix” Style Attack

Cybersecurity researchers continue to track sophisticated "Click Fix" style distribution campaigns that deliver the...

Fake BianLian Ransom Demands Sent via Physical Letters to U.S. Firms

In a novel and concerning development, multiple U.S. organizations have reported receiving suspicious physical...