Logo
/
Blog/Analysis of Cyber Intrusions Targeting Major Religious Organizations in South Korea
October 6, 202627 min readCyber Threat Intelligence
Share:

Analysis of Cyber Intrusions Targeting Major Religious Organizations in South Korea

By Threat Intelligence Unit

Overview

Oasis Security analyzed files from an attacker server used against two of South Korea's largest churches, [Victim A] and [Victim B]. A web shell on [Victim A]'s ERP led to sysadmin access and the collection of member, financial, and administrative data. [Victim B] was compromised using previously leaked credentials and IDOR vulnerabilities affecting its groupware and SIMS systems, followed by access to SAP and the identification of assets associated with its college ministry, GitHub, and Firebase.



Executive Summary

  • Files were collected from 192.3.239.164 (United States) between 28 August and 1 September 2026
  • [Victim A]: ERP web shell → [ERP] reverse engineering → MSSQL xp_cmdshell and linked-server RCE → DB monitoring solution bypass, NAS access, and MinIO staging (47.3 GB)
  • [Victim B]: leaked credentials and IDOR across EKP and SIMS, followed by SAP access through groupware SSO; MinIO credentials from an earlier compromise of a U.S. Christian platform were reused to stage [Victim A] data


Infrastructure Analysis

  • IP Address: 192.3.239.164
  • Geolocation: United States

[Victim A]_loot held [Victim A] dumps, tooling, and an operator report. pentest/[Victim B] held the [Victim B] equivalent.

Exfiltrated Victim A TSV dumps including member payroll and accounting tables

Figure 1. Exfiltrated [Victim A] dumps in [Victim A]_loot, including member, payroll, and accounting tables

Victim B pentest directory with employee JSON SIMS dumps and photos

Figure 2. [Victim B] collections in pentest/[Victim B], including employee JSON, SIMS dumps, and photos


[Victim A] Attack Flow and Damage Scope

ERP to MinIO exfiltration

Victim A intrusion workflow

Mass login attempts against churches, an ERP web shell, [ERP] decryption, linked-server xp_cmdshell, a DB monitoring solution bypass, and MinIO staging.

47.3 GB
Victim A DB dump
330K
donation / RR records
68K
approval documents
3
linked-server RCE targets

Phase 1

Initial access

  1. 01Mass login attemptsobserved`login_results_v3.json`: 197 attempts against South Korean churches, including Victim A.
  2. 02Web shell on ERPobserved`codex_x.aspx` in the [ERP] web root; still reachable on 9 September 2026.

ERP web shell liveExecution as the ERP application-pool account.

Phase 2

Privilege and lateral movement

  1. 03[ERP] reverse engineeringobserved`Security.dll` reversed; `ServerSetting.xml` decrypted to MSSQL sysadmin.
  2. 04Linked-server xp_cmdshell RCEobservedJANRO, MIS, and LMS_MIS mapped as `sa` for remote `xp_cmdshell`.
  3. 05DB monitoring solution bypass and MariaDB rootobservedUNC `V$`/`W$` bypassed the local-volume block; `global_priv.MAD` cracked for MariaDB root.

Internal databases readableMIS, LMS_MIS, JANRO, FTP, and MariaDB/XIM in scope.

Phase 3

Collection and staging

  1. 06NAS via hardcoded credentialsobservedHardcoded credentials enabled SMB access from MIS1 to [Victim A-NAS].
  2. 07MinIO exfiltrationobservedDumps uploaded to a pre-positioned MinIO bucket; 47.3 GB (13,939 files) recovered.

Data staged off-networkThird-party transfers mean recovered volume is a lower bound.

Victim A
Confirmed collections
DataScale
Production DB6,507 tables (Common 1,178, FGPRAY 5,752)
Core tablesMember, duty, payroll, accounting (TCRMemberArea, TCRMemberDutyRec, TPRPayResult, MIS_AC_SLIPD)
Administrative PIIGJ_USER01, AC_USER01, AD_USER01 → siteb_pii_full.tar.gz
LMS_MIS sensitive tablesLibrary PII (DLIDB3), access-control data (Membership_new) → lms_mis_sensitive.tar.gz
JANRO church / administrative DBsdigiwave, DEACONESS, kis_user01, 21 databases
NAS reportsoz70 9,577 reports from [Victim A-NAS]; ~63 TB remaining on the volume
Chat DB (xim)6,807 users, 18,105 messages, 2,585 attachments
OtherMail (xclickr31_[Victim A]), 6,874 login accounts

Identification of [Victim A] and Web Shell Upload

login_results_v3.json recorded 197 login attempts against South Korean churches, including [Victim A]'s mis.[Victim A].com.

login_results_v3.json entry highlighting mis Victim A domain

Figure 3. login_results_v3.json identifying mis.[Victim A].com among church login targets

HANDOVER_REPORT.md records that codex_x.aspx was uploaded to D:\[ERP]\[Victim A]_WK and ran as iis apppool\[Victim A]_wk. As of 9 September 2026, the shell was still reachable from the internet.

Operator notes on the WAS2 webshell URL path and control scripts

Figure 4. Operator notes on the WAS2 web shell at codex_x.aspx, including ws.sh / wssql.sh wrappers

Summary line for WAS2 webshell and iis apppool account

Figure 5. WAS2 web-shell summary: URL, application-pool identity, and cmd / sql / file / info modes

Browser request to mis Victim A codex_x.aspx still returning MODE prompt

Figure 6. codex_x.aspx still responding on mis.[Victim A].com at the time of analysis


Initial Lateral Movement and [ERP] Reverse Engineering

ws.sh sent a POST request to the web shell to run cmd.exe /c on WAS2 and scan 10.10.***.***/24. Identified hosts: WAS2 ERP ([Victim A-INT A-IP-1], public 114.200.***.***); WAS1 ([Victim A-INT A-IP-2], Replix/MCCS/BSR); IIS ([Victim A-INT A-IP-3]); MIS1 ([Victim A-INT A-IP-4], MSSQL/MariaDB/DB monitoring solution/ABB); MIS2 ([Victim A-INT A-IP-5]); NAS ([Victim A-INT A-IP-6]); nginx ([Victim A-INT A-IP-7], gw.[Victim A].com, RDP).

CREDENTIAL_AND_SYSTEMS.md records reverse engineering of [ERP] Security.dll (AES, DES, custom Base64). Decrypting ServerSetting.xml yielded MSSQL (MISV) sysadmin on four databases. xp_cmdshell was enabled, and the service account had SeImpersonate.

Operator notes on [ERP] Security.dll AES DES and custom base64

Figure 7. Operator notes on reversing [ERP] Security.dll (AES-256, DES, custom Base64)

Decrypted ServerSetting.xml MSSQL connection entries with credentials redacted

Figure 8. Decrypted ServerSetting.xml MSSQL connection entries for MISV (credentials redacted)

MIS1 MSSQL xp_cmdshell sysadmin and SeImpersonate summary

Figure 9. MIS1 MSSQL summary: xp_cmdshell, sysadmin, and SeImpersonate

From MISV, linked-server reconnaissance identified JANRO ([Victim A-INT B-IP-1]), LMS_MIS ([Victim A-INT B-IP-2]), MIS ([Victim A-INT B-IP-3/4/5/6]), MariaDB ([Victim A-INT B-IP-7]), and an internal FTP host ([Victim A-INT B-IP-8], Insapic). JANRO, MIS, and LMS_MIS used remote_name=sa, so EXEC() AT [LINK] could run xp_cmdshell remotely via lq_cmd.sh / q.sh.

Operator notes on JANRO MIS LMS_MIS linked servers mapped as sa

Figure 10. MISV linked servers JANRO, MIS, and LMS_MIS mapped as sa for remote xp_cmdshell

lq_cmd.sh and q.sh posting xp_cmdshell through the webshell

Figure 11. lq_cmd.sh and q.sh sending xp_cmdshell through codex_x.aspx


Secondary Lateral Movement with xp_cmdshell RCE

rce.sh used local xp_cmdshell to create a temporary SYSTEM service on a remote host. That path was used against the EFAM file server and MIS ([Victim A-INT A-IP-5]), then reused against MIS, LMS_MIS, and JANRO.

rce.sh creating a temporary SYSTEM service over xp_cmdshell

Figure 12. rce.sh creating a temporary SYSTEM service on a remote host via xp_cmdshell

Operator notes on EFAM file-server SYSTEM RCE

Figure 13. Operator notes on SYSTEM RCE against the EFAM file server

On MIS, more than 40 databases were enumerated, including GJ_USER01 (members), AC_USER01 (accounting), and digiwave (access control).

MIS database inventory including GJ_USER01 AC_USER01 and digiwave

Figure 14. MIS database inventory, including GJ_USER01, AC_USER01, and digiwave

A Base64-encoded DB monitoring solution master key (KS_SERVER.SERVER_MK) was recovered. KS_APPLIST listed DBA tools such as Toad/SQL Developer as monitoring targets.

DB monitoring solution master key and monitored DBA tool list

Figure 15. DB monitoring solution master key and KS_APPLIST entries for DBA tools

LMS_MIS held about 41.2 GB of databases, including TB_ADMIN / userID and copies of GJ_USER01 / AC_USER01. 75 sensitive tables, including DLIDB3 and Membership_new, were packaged as lms_mis_sensitive.tar.gz.

LMS_MIS database sizes and privileged account notes

Figure 16. LMS_MIS database sizes and privileged-account notes

LMS_MIS sensitive table dump packaged as lms_mis_sensitive.tar.gz

Figure 17. LMS_MIS sensitive-table dump packaged as lms_mis_sensitive.tar.gz

JANRO, a development host, yielded full dumps of 21 databases, including kis_user01, digiwave, DEACONESS, and JANGRO.

JANRO database inventory across 21 church and administrative databases

Figure 18. JANRO inventory across 21 church and administrative databases

Internal FTP was reachable with the insapic account from MISV reconnaissance. GJ_Picture listed 60,891 resident-registration photos (SDNO.jpg).

Internal FTP GJ_Picture resident-registration photo store notes

Figure 19. Internal FTP GJ_Picture store of resident-registration photos (SDNO.jpg)


DB Monitoring Solution Bypass and MariaDB Root

The DB monitoring solution SecureFilter on port 5001 blocked dir V:\. SMB administrative shares \\127.0.0.1\V$ and \\127.0.0.1\W$ bypassed the filter. Volume V held MariaDB data (global_priv.MAD) and MSSQL files ([Victim A]_Primary.mdf 116 GB, log 430 GB). Volume W held MSSQL daily backups (xclickr31 ~23.7 GB; Common ~21.8 GB).

The hash in global_priv.MAD was cracked with SHA1(SHA1(password)). The recovered MariaDB root password matched the XIM / xclick administrator password.

Operator notes on DB monitoring solution UNC bypass and MariaDB root hash crack

Figure 20. DB monitoring solution UNC bypass, global_priv.MAD crack, and volumes V:/W:


NAS Access via Hardcoded Credentials

ws.sh against NAS ([Victim A-INT A-IP-6]) found a 5 July 2024 EXT backup with web.config and KakaoTalk API material, plus hardcoded NAS credentials. Matching credentials were also in the ABB agent's system-db.sqlite on MIS1.

From MIS1, net use could reach [Victim A-NAS] over SMB. The volume had about 63 TB remaining. DSM web login failed.

EXT site backup path containing web.config and Kakao API material

Figure 21. EXT backup on the NAS containing web.config and Kakao API material

Hardcoded NAS credentials in EXT web.config with values redacted

Figure 22. Hardcoded NAS credentials in EXT web.config (values redacted)

ABB agent token authentication for the NAS backup share

Figure 23. ABB agent token used against the NAS backup share

Synology inventory for Victim A-NAS including oz70 reports and 63 TB remaining

Figure 24. Synology inventory for [Victim A-NAS], including [ERP]/oz70; about 63 TB remaining


Exfiltration through Pre-Positioned MinIO

Dumps from MIS / LMS_MIS / JANRO / FTP, V:/W: after the DB monitoring solution bypass, and NAS objects were staged on MIS1 at D:\export and uploaded to a previously compromised MinIO bucket.

79 major dumps, including GJ_USER01 and AC_USER01, were driven by siteb_pii_full.bat, which BCP-exported tables to D:\export, packed them as siteb_pii_full.tar.gz, and uploaded the archive to MinIO.

siteb_pii_full.bat BCP export commands for GJ_USER01 tables

Figure 25. siteb_pii_full.bat BCP export of GJ_USER01 tables to D:\export

siteb_pii_full.tar.gz upload to MinIO a-bucket

Figure 26. Upload of siteb_pii_full.tar.gz to the MinIO a-bucket

janro_gen.py generated janro_full2.bat for the same BCP-and-upload pattern against JANRO and kis_user01. janro_push2.py pushed that batch through the web shell.

janro_gen.py generating BCP batch and MinIO upload commands

Figure 27. janro_gen.py generating BCP commands and MinIO uploads for JANRO and kis_user01

janro_full2.bat BCP tar and MinIO PUT for church databases

Figure 28. janro_full2.bat BCP, tar, and MinIO PUT for janro_church_dbs.tar.gz and kis_erp_full.tar.gz

janro_push2.py sending janro_full2.bat through the webshell in chunks

Figure 29. janro_push2.py pushing janro_full2.bat through the web shell in chunks

cloud_pull.py pulled the MinIO objects back onto the attacker server. cloud_pull.log recorded 69 retrieved files and 37 skips. 22 of those objects were still in [Victim A]_loot.

cloud_pull.py listing and downloading objects from MinIO

Figure 30. cloud_pull.py listing and downloading objects from MinIO into [Victim A]_loot

cloud_pull.log HTTP 200 results for member payroll and accounting TSV files

Figure 31. cloud_pull.log HTTP 200 results for member, payroll, and accounting TSV files

Recovered TSV dump sizes for member payroll and accounting tables

Figure 32. Recovered TSV sizes for member, payroll, and accounting tables

The same directory held NAS data from [ERP]\oz70.

Exfiltrated OZ Report files from [ERP] oz70 on the NAS

Figure 33. OZ Report files from [ERP]\oz70 on the NAS

The cracked MariaDB password also unlocked xclick. xclickr31_user.tsv held 6,874 accounts. The exfiltrated data also included approximately 960,000 congregant records updated within the previous two years, including names and resident registration numbers. Related dumps include about 14,000 chats, 330,000 donation records, and 68,000 document-creation records.

xclickr31 user TSV and related JAR files in the loot directory

Figure 34. xclickr31_user.tsv and related xclick components in the loot directory

Redacted xclick user table showing names teams and email domains

Figure 35. Redacted xclick user rows, including names, teams, and email domains

Exported chat approval and donation text dumps with record counts

Figure 36. Exported chat, approval, and donation dumps (~14,706 chats, ~68K approvals, ~331K donations)


[Victim B] Compromise and Data Exfiltration

[Victim B] was targeted before [Victim A]: groupware → SIMS → SAP → assets associated with the college ministry, GitHub, and Firebase.

Victim B
Tools, techniques, and collections
TechniqueWhat was taken
SIMS UserInfoSearch (IDOR)Arbitrary-user plaintext PIN, login ID, mobile, email
UserInfoManagementPasswordSave / UserInfoSavePassword reset/change on arbitrary accounts
SAP portal getEmpList / getPersonInfoHR for 286 people (including the senior pastor) and 228 organization-tree entries
goPageSIMS / goPageSMART (SSO)Authentication tokens for arbitrary employees
EKP bulletin board and approval APIs114 posts and 106 electronic-approval documents on gw.[Victim B].org
[Victim B]-univ APIUnauthenticated student/staff PII, QR ticket IDOR, leader mobile login
GitHub public-source review17 public repositories related to [Victim B]
Open FirebaseStorage allow read/write: if true; hardcoded DB and seed credentials
WAF bypass and credential reuseAll reused passwords expired or deleted; no successful login
Captured web contextLogin, user-log, and SMART portal error screens

Per-phase reports sat under pentest/[Victim B].

Victim B pentest markdown reports including groupware SIMS and WAF notes

Figure 37. [Victim B] pentest reports covering groupware, SIMS, APIs associated with the college ministry, and WAF tests

Recon located subdomains, about 20 IPs, and core systems (Naver WAF, SAP, EKP, SIMS).

Victim B asset overview with SAP EKP SIMS Exchange and WAF notes

Figure 38. [Victim B] asset overview: SAP, EKP, SIMS, Exchange, and Naver WAF

result_.[Victim B].org_20260525_215444.xlsx lists older leaked credentials per subdomain. Groupware account hj*** was then used against EKP (gw.[Victim B].org) to call organizational-chart and employee APIs without authorization.

Leaked credential spreadsheet highlighting gw EKP login for hj account

Figure 39. Leaked-credential spreadsheet highlighting gw.[Victim B].org EKP login for hj***

Operator notes on EKP employee-info API and approval IDOR tests

Figure 40. Operator notes on EKP employee-info APIs and electronic-approval IDOR tests

groupware_data.json and groupware_full.json contain records for 10 of 383 exfiltrated employees (empList).

Redacted groupware JSON with organization tree and employee fields

Figure 41. Redacted groupware JSON with organization-tree and employee fields

On SIMS (sims.[Victim B].org), the same hj*** session was used to read other users' plaintext PINs through IDOR and then reset a manager-privileged account. In addition, personal information belonging to approximately 89,000 congregants was found among the exfiltrated data.

SIMS UserInfoSearch IDOR notes for plaintext PIN disclosure

Figure 42. SIMS UserInfoSearch IDOR allowing plaintext PIN disclosure from a member session

SIMS password reset and profile-update API notes

Figure 43. SIMS UserInfoManagementPasswordSave / UserInfoSave password-reset chain

sims_special_accounts.json held 1,419 sensitive records.

SIMS JSON dumps including members_all and special_accounts

Figure 44. SIMS JSON dumps, including sims_members_all.json and sims_special_accounts.json

Redacted SIMS special-account rows with emails and phone numbers

Figure 45. Redacted SIMS special-account rows (emails and phone numbers)

Groupware SSO (goPageSMART) reached the SAP portal without a second login and yielded 286 HR records plus 96 employee photos.

Operator notes on SAP portal HR directory dump via groupware SSO

Figure 46. SAP portal HR directory dump via groupware SSO (getEmpList / getPersonInfo)

Operator notes on exporting 96 employee photos from SAP Content Server

Figure 47. Export of 96 employee photos from the SAP Content Server

employees JSON files and sap_hr_employees.json in the pentest directory

Figure 48. employees_*.json and sap_hr_employees.json in the pentest directory

A total of 286 employee records were identified among the collected data.

Redacted employee JSON record with department and pastor title fields

Figure 49. Redacted employee JSON record (department and role fields)

Cookie files contained data from the initial member session and subsequently obtained sessions.

SIMS and SAP cookie files for member manager and admin sessions

Figure 50. SIMS and SAP cookie files for member, manager, and admin sessions

The same directory held captured pages.

Captured SAP and groupware HTML pages and HR dump scripts

Figure 51. Captured SAP/groupware HTML pages and HR-dump scripts

Unauthenticated slug enumeration on [Victim B]-Univ univ-group-info returned staff names, phones, and bank-account fields. unashamed_univgroupinfo.json held eight such records.

Unauthenticated university group-info API returning staff PII and bank accounts

Figure 52. Unauthenticated [Victim B]-Univ univ-group-info API returning staff PII and bank accounts

University API loot including QR codes and univgroupinfo JSON

Figure 53. University API loot, including QR codes and unashamed_univgroupinfo.json

Firebase storage allowed unrestricted read and write (allow read/write: if true), with hardcoded database and seed credentials.

GitHub public-repo sync and open Firebase rules with hardcoded keys redacted

Figure 54. GitHub public-repo sync and open Firebase rules with hardcoded keys (redacted)

WAF-bypass and credential-reuse attempts failed; all reused passwords had expired or been deleted. Remaining notes include a 2016 OWA endpoint and a possible cppm subdomain-takeover risk.

Failed credential-reuse attempts across Victim B login portals

Figure 55. Failed credential-reuse attempts across [Victim B] login portals

Operator follow-on notes on SQLi OWA CVE and cppm subdomain takeover

Figure 56. Operator follow-on notes: SQLi on a legacy ASP host, Exchange 2016 OWA, and cppm subdomain takeover


Conclusion

Neither case was a one-step intrusion. The [Victim A] compromise progressed from an ERP web shell to database administrator privileges, linked-server RCE, and MinIO staging. The [Victim B] compromise progressed from leaked credentials and IDOR to access across groupware, SIMS, SAP, and assets associated with the college ministry and Firebase.

The same operator had previously targeted a U.S. Christian content platform. MinIO administrator credentials from the U.S. compromise were reused to stage [Victim A] data, linking the two South Korean church intrusions to previously used infrastructure.

By using AI, attackers can rapidly carry out lateral movement, reverse engineering, vulnerability analysis, and data exfiltration. This can shorten the time between initial access and a broader compromise, leaving defenders less time to detect and contain an intrusion before it spreads across internal systems and exposes sensitive data.