Threat Profile & Target Surface
ORIGIN & THEATER
China / Asia-Pacific
Observed active infrastructure & staging OPERATIONAL STATUS
ACTIVE
First Seen: 2026-05 | Last: 2026-08 TARGETED SECTORS & VERTICALS
🎯 Healthcare & Health Commissions (卫生健康委员会)🎯 Municipal Portals & Government Administration🎯 Enterprise Java / Spring Cloud Backends
WEAPONRY & TOOLING ARSENAL
⚔️ Cobalt Strike 4.9.1 (TeamServer)⚔️ CrossC2 (genCrossC2.Linux)⚔️ Adaptix C2 Framework⚔️ RRR_C2 Custom Mod (v1.2)⚔️ Rogue MySQL Server (Arbitrary File Read)⚔️ JNDIExploit / Marshalsec⚔️ ENScan_GO Enterprise Recon⚔️ Impacket SMB Server
Intelligence Telemetry & Findings
Key Operational Findings
- Infrastructure Staging: Host
101[.]42[.]255[.]92operates as a centralized Command & Control hub and offensive staging node hosted on Tencent Cloud. - Dual C2 Backbone: Runs Cobalt Strike 4.9.1 on port
8081alongside the modern AdaptixC2 and customizedRRR_C2_v1.2frameworks. - Specialized Protocol Attack: The cluster leverages Rogue MySQL Server (port 3306) to abuse MySQL’s
LOCAL INFILEprotocol feature, forcing connected Java/Spring clients to exfiltrate arbitrary files (application-dev.yml, internal.jarpackages). - Targeting Vertical: Direct reconnaissance against municipal and public health administration infrastructure (
卫生健康委员会).
Technical Telemetry & Indicators
| Indicator Type | Defanged Value | Operational Role |
|---|---|---|
| IPv4 Address | 101[.]42[.]255[.]92 | Staging, Cobalt Strike & Adaptix C2 Node |
| Port / Service | 101[.]42[.]255[.]92:8081 | Cobalt Strike TeamServer Listener |
| Port / Service | 101[.]42[.]255[.]92:3306 | Rogue MySQL Arbitrary File Exfiltration Listener |
| Port / Service | 101[.]42[.]255[.]92:8555 | JNDI / HTTP Payload Delivery |
| Port / Service | 101[.]42[.]255[.]92:8857 | Interactive Reverse Shell Listener |
| Tool Artifact | genCrossC2.Linux | Cross-platform Linux ELF Cobalt Strike Beacon Compiler |
| Tool Artifact | rogue_mysql_server | JDBC Protocol Arbitrary Client File Extraction Tool |
MITRE ATT&CK Framework Mapping
| Tactic / ID | Observed Adversary Technique & Context |
|---|---|
| T1190 | Exploit Public-Facing Application (Fastjson/JNDI/Log4j) |
| T1552.001 | Credentials in Files (Rogue MySQL application-dev.yml extraction) |
| T1059.004 | Unix Shell |
| T1562.001 | Disable or Modify Tools (Tencent Cloud YunJing EDR uninstallation) |
| T1071.001 | Web Protocols (Adaptix/Cobalt Strike HTTPS C2) |
| T1596 | Search Open Technical Databases (ENScan_GO) |
| T1090.003 | Multi-hop Proxy (Automated Proxy Pool) |
Chronological Operational Timeline
VPS Provisioning & EDR Neutralization
Host 101[.]42[.]255[.]92 provisioned on Tencent Cloud; attacker systematically executed uninstallers to terminate YunJing/YDEdr security monitoring.
Adaptix & Cobalt Strike 4.9.1 TeamServer Deployment
Operator compiled and established persistent systemd daemons for AdaptixC2 and launched Cobalt Strike 4.9.1 TeamServer with CrossC2 payload generation.
Healthcare Reconnaissance Campaign
Execution of ENScan_GO enterprise asset scanners against regional Health Commissions (卫生健康委员会) and municipal service portals.
Rogue MySQL Server & JNDI Exploitation
Active exploitation using Rogue MySQL to weaponize JDBC client file-read capabilities against Java spring backends, retrieving application-dev.yml configs.