While sweeping open directories on
@etugenio, I came across a server in the US🇺🇸 on PEG TECH's network with port 8888 exposed. It wasn't a victim, but rather a box where a Chinese🇨🇳 speaking operator had left their entire offensive arsenal exposed to the internet. At the center of it was an AI-driven pentest framework.
The operator calls it "Sinian." It organizes each attack technique into its own SKILL.md playbook, while sinian_pipeline.py chains them together into an autonomous attack pipeline. The same environment also hosts a plugin-based webshell C2 with modules for lateral movement, database dumping, SOCKS proxying, persistence, and log timestomping.
The targets include Chinese payment and virtual-goods platforms such as tokenpay, dujiaoka, acg-faka, and epay, whose source trees were exposed through publicly accessible .git repositories. The attacks appear to rely on a ThinkPHP deserialization chain. Tooling targeting Shanghai health-card and Guangxi police-certificate systems also suggests that the operation extends into account-opening and real-name verification fraud. Stolen data is exfiltrated to a Telegram bot.
Host:
app.etugen.io/trashpile/104.…
Content: Sinian AI pentest toolkit + webshell C2 + qingmeng-backdoor
Exfiltration: Telegram bot
Framework: CyberStrikeAI
Exploits: CVE-2024-44902 - CVE-2025-63888 - phpggc
Targets: tokenpay - dujiaoka - acg-faka - epay
Fraud tooling: shanghai_health_card.py - guangxi_police_cert.py
ATT&CK: T1059.004/.006 · T1552.003 · T1530 · Webshell
#CTI #opendir #usa #china #war #hack #webshell