Contents
The first signal
The engagement started with a support ticket. Multiple customers reported a “verification” page they had never seen before — one that asked them to press Win+R, paste a snippet, and hit Enter. Click-fix social engineering, except the lure was being served from the client’s own subdomain.
The infrastructure was a shared cPanel install fronted by Cloudflare. By the time we joined, both layers had been compromised for weeks.
First 48 hours: contain without losing evidence
Containment had to happen before forensics, but not at the cost of forensics. The first forty-eight hours focused on three concurrent workstreams:
- Cloudflare coordination. WAF rules were applied immediately to block the malicious paths at the edge while we cleaned origin. This bought us time to investigate without users continuing to see the lure.
- Evidence preservation. Full disk and memory snapshots were captured from affected hosts before any credential rotation. We could not afford to lose attacker artefacts to a panic restart.
- Credential lockdown. All cPanel users, DNS API tokens, and shared SSH keys were rotated under cover of an existing maintenance window. New origin IPs were brought up; old IPs were retired only after we confirmed nothing critical still pointed at them.
Investigation
The attacker had been in for approximately six weeks. Reconstruction of the kill chain:
- Initial access — an undisclosed cPanel zero-day, exploitable from any authenticated low-privilege user account. Coordinated disclosure to the vendor was initiated during the engagement; CVE assignment is pending public release.
- Privilege escalation — the zero-day chained into administrative API access on the cPanel install.
- Persistence — a malicious cron job running as the cPanel user, plus a templated webshell hidden inside a sub-folder of one of the marketing sites.
- Weaponisation — the lure pages were server-side rendered with templates that varied user-agent and referrer-based triggers. Static-content scanners had repeatedly walked the URLs and seen nothing suspicious because the templates did not fire for crawler signatures.
Eradication and recovery
Eradication ran in parallel with the investigation. The webshells were removed, the malicious cron entries deleted, the templated routes audited line-by-line, and the cPanel install patched once the vendor shipped an emergency fix.
Final recovery required full rebuilds of two of the worst-affected subdomains where the attacker had modified shipping templates in ways that were difficult to confidently revert. For the remaining subdomains, the existing code was restored from a known-clean backup snapshot pre-dating the compromise window.
Hand-over
The engagement closed with a full timeline reconstruction, attacker-TTP documentation mapped to MITRE ATT&CK, Sigma rules for the SOC to detect the same persistence pattern elsewhere, and a YARA signature for the dropper. A 30-day retest verified no re-entry attempts had succeeded.
The client retained 8bytes on a quarterly retainer post-incident.
Tags