Determined Attacker Uploads Malicious Webshells to Parks and Rec Management Platform Servers
Cybersecurity Classified by Officially
Huntress recently observed three web servers compromised via a vulnerability in a popular web-based recreation management software platform designed for local municipalities, parks, and recreation organizations.
After multiple failed attempts, the threat actor gained access by exploiting a flaw in the platform's file upload function, then used the same technique across all three servers: register a new account, abuse the member files upload function to launch webshells, and ultimately steal payment card data.
User-agent strings suggest that the threat actor is based in China. We also suspect the use of AI-generated scripts throughout the kill chain, from the large number of failed initial access probes to the final upload of PowerShell scripts with extensive comments in the provided instructions.
The threat actor may have suspected that we were onto them: They changed tactics after compromising the second web server, adopting more defense evasion techniques such as renaming files and manipulating timestamps in metadata.
When one of the servers was brought back into production prematurely, the threat actor returned to launch a wider attack on the platform's users by injecting a trojan within the authentication page that harvests credentials in real time.
Acknowledgments: Special thanks to Olly Maxwell for his contributions to this investigation and write-up.
On September 10, 2026, Huntress observed a threat actor compromising multiple tenants on a shared recreation management software platform using one repeatable trick: register a member account, upload a malicious file, and turn it into a webshell.
The webshells were used to execute malicious activity across three web servers. Attempting to identify and extract sensitive information, they enumerated and probed the payment/secure tenant and planted disguised copies where its folders existed.
This is an extract. The publication continues at the source.
Read the original at the source: https://www.huntress.com/blog/parks-recreation-platform-webshell-attack
Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Huntress — imported from official source
- Official source
- https://www.huntress.com/blog/rss.xml RSS
- Imported
- October 01, 2026 03:00
- Versions
- 1 recorded
- Identity
https://www.huntress.com/blog/parks-recreation-platform-webshell-attack