Back Gbhackers Hackers Use ERP Web Shell and IDOR Flaws to Breach Major South Korean Churches
Attackers breached two of South Korea’s largest churches through distinct intrusion chains, combining an ERP web shell, privileged database access, leaked credentials, and broken authorization controls.
Oasis Security’s analysis of attacker-server files documents extensive collection of congregant, employee, financial, and administrative information across both organizations.
Its findings describe recovered attacker artifacts, rather than a complete accounting of every system accessed or every file transferred.
At Victim A, the attacker deployed codex_x.aspx inside the ERP web root, executing commands under the IIS application-pool identity.
Operator records also documented 197 login attempts against South Korean churches. The web shell remained internet-accessible when checked on September 9, according to the investigation.
Reverse engineering the ERP’s Security.dll exposed encryption routines that protected configuration secrets.
Decrypting ServerSetting.xml yielded MSSQL credentials with sysadmin privileges, enabling database enumeration and operating-system command execution through xp_cmdshell.
Linked-server mappings extended that access to JANRO, MIS, and LMS_MIS using the privileged sa account.
Microsoft documents that xp_cmdshell launches Windows commands under the SQL Server service account when invoked by privileged users, making excessive database permissions particularly consequential.
The attacker subsequently used temporary Windows services to obtain SYSTEM execution on additional hosts.
A database-monitoring control blocked local-volume access but failed to prevent equivalent access through loopback SMB administrative shares.
Retrieved MariaDB authentication material was cracked, revealing a root password reused by the organization’s chat platform.
Oasis Security analyzed that , collected files from the United States-hosted server at 192.3.239.164 between August 28 and September 1, 2026. The supplied investigation identifies the churches as Victim A and Victim B.
Hardcoded credentials recovered from backup configuration files and an agent database also enabled SMB access to a NAS.
The investigation reports collection of database exports, administrative documents, payroll information, accounting records, resident-registration photographs, and messaging data.
Victim A’s recovered collection totaled 47.3 GB across 13,939 files. Approximately 960,000 congregant records included names and resident registration numbers, alongside roughly 330,000 donation records and 68,000 approval documents.
Database tables were exported into a staging directory, archived, and uploaded to a previously compromised MinIO bucket.
Credentials associated with an earlier intrusion against a U.S. Christian platform were reused for this staging infrastructure.
Because additional transfers involved third-party storage, the recovered volume represents a lower bound, not the confirmed total exposure.
Victim B’s intrusion began with previously leaked groupware credentials. The attacker exploited insecure direct object reference flaws across EKP and SIMS to retrieve other users’ information, expose plaintext PINs, and reset a manager-level account.
Groupware single sign-on subsequently provided SAP portal access without another login. Collected material included approximately 89,000 congregants’ personal information, 286 employee records, and 96 employee photographs.
Follow-on reconnaissance identified unauthenticated college-ministry APIs, QR-ticket authorization weaknesses, 17 public GitHub repositories, and Firebase storage rules permitting unrestricted reads and writes.
Separate credential-reuse attempts failed because the tested passwords had expired or been deleted.
The chains highlight failures in secret management, database privilege boundaries, and object-level authorization. Defenders should restrict linked-server privileges, rotate exposed secrets, investigate web-shell activity, and review cloud-storage rules.
OWASP recommends checking authorization for every requested object; authentication alone does not prevent IDOR. Organizations should also validate password-reset ownership and permissions before issuing cross-system SSO tokens to users.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC .
Artificial Intelligence
Cyber security Course
Cyber Security Resources
Cybersecurity
Information Gathering
Information Security Risks
Critical Progress DataDirect GenAI Flaw Lets Attackers Execute Arbitrary OS Commands
Russian-Speaking CyberXero Uses AI Agent Swarm to Attack Ukrainian Energy Infrastructure
FBI Warns FortiBleed Campaign Targeting Fortinet Firewalls and VPNs to Steal Credentials
OpenSSH 10.6 Fixes Security Flaws Including SSH Plaintext Recovery Attack
LUNEXSTEALER Gives Hackers Remote Control of Browsers Through Malicious Chrome Extension
Elastic Patches 14 Security Flaws, Including One Enabling Cross-Tenant Data Interception
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
