Contents
What started as a routine support ticket — users reporting odd CAPTCHA popups on a marketing subdomain — turned into a two-week engagement containing an attacker who had quietly weaponised a cPanel zero-day to take over more than sixty subdomains across the estate.
The initial signal
The first sign was banal. A handful of customers reported a “verification” page they had never seen before, which asked them to press Win+R, paste a snippet, and hit Enter. Classic click-fix social engineering — except the lure page was being served from the client’s own subdomain.
The hosting layer was cPanel-on-shared-IP, fronted by Cloudflare. Both layers had been compromised by the time we arrived.
Containment
The first 48 hours focused on stopping bleeding without losing evidence:
- Identified the zero-day in the cPanel install (CVE pending coordinated disclosure)
- Coordinated with Cloudflare to take down the malicious paths via WAF rules while we cleaned the origin
- Snapshotted disk and memory across affected hosts before any rotation
- Rotated all cPanel and DNS credentials, with new IPs swapped under cover of an existing maintenance window
What we found
The attacker had been in for roughly six weeks. Initial access came via the zero-day. Persistence was a malicious cron entry running as the cPanel user, plus a webshell hidden inside a sub-folder of one of the marketing sites. The lure pages were templated and rendered server-side, which is why none of the static-content scanners had picked them up.
A full timeline and remediation roadmap was delivered to the client at engagement close. Detection content (Sigma rules and a YARA signature for the dropper) was handed over for ongoing hunting.
Tags