Analysis of Cyber Intrusions Targeting Major Religious Organizations in South Korea
By Threat Intelligence Unit
Overview
Oasis Security analyzed files from an attacker server used against two of South Korea's largest churches, [Victim A] and [Victim B]. A web shell on [Victim A]'s ERP led to sysadmin access and the collection of member, financial, and administrative data. [Victim B] was compromised using previously leaked credentials and IDOR vulnerabilities affecting its groupware and SIMS systems, followed by access to SAP and the identification of assets associated with its college ministry, GitHub, and Firebase.
Executive Summary
- Files were collected from 192.3.239.164 (United States) between 28 August and 1 September 2026
- [Victim A]: ERP web shell → [ERP] reverse engineering → MSSQL xp_cmdshell and linked-server RCE → DB monitoring solution bypass, NAS access, and MinIO staging (47.3 GB)
- [Victim B]: leaked credentials and IDOR across EKP and SIMS, followed by SAP access through groupware SSO; MinIO credentials from an earlier compromise of a U.S. Christian platform were reused to stage [Victim A] data
Infrastructure Analysis
- IP Address: 192.3.239.164
- Geolocation: United States
[Victim A]_loot held [Victim A] dumps, tooling, and an operator report. pentest/[Victim B] held the [Victim B] equivalent.
Figure 1. Exfiltrated [Victim A] dumps in [Victim A]_loot, including member, payroll, and accounting tables
Figure 2. [Victim B] collections in pentest/[Victim B], including employee JSON, SIMS dumps, and photos
[Victim A] Attack Flow and Damage Scope
ERP to MinIO exfiltration
Victim A intrusion workflow
Mass login attempts against churches, an ERP web shell, [ERP] decryption, linked-server xp_cmdshell, a DB monitoring solution bypass, and MinIO staging.
Phase 1
Initial access
- 01Mass login attemptsobserved`login_results_v3.json`: 197 attempts against South Korean churches, including Victim A.
- 02Web shell on ERPobserved`codex_x.aspx` in the [ERP] web root; still reachable on 9 September 2026.
ERP web shell liveExecution as the ERP application-pool account.
Phase 2
Privilege and lateral movement
- 03[ERP] reverse engineeringobserved`Security.dll` reversed; `ServerSetting.xml` decrypted to MSSQL sysadmin.
- 04Linked-server xp_cmdshell RCEobservedJANRO, MIS, and LMS_MIS mapped as `sa` for remote `xp_cmdshell`.
- 05DB monitoring solution bypass and MariaDB rootobservedUNC `V$`/`W$` bypassed the local-volume block; `global_priv.MAD` cracked for MariaDB root.
Internal databases readableMIS, LMS_MIS, JANRO, FTP, and MariaDB/XIM in scope.
Phase 3
Collection and staging
- 06NAS via hardcoded credentialsobservedHardcoded credentials enabled SMB access from MIS1 to [Victim A-NAS].
- 07MinIO exfiltrationobservedDumps uploaded to a pre-positioned MinIO bucket; 47.3 GB (13,939 files) recovered.
Data staged off-networkThird-party transfers mean recovered volume is a lower bound.
| Data | Scale |
|---|---|
| Production DB | 6,507 tables (Common 1,178, FGPRAY 5,752) |
| Core tables | Member, duty, payroll, accounting (TCRMemberArea, TCRMemberDutyRec, TPRPayResult, MIS_AC_SLIPD) |
| Administrative PII | GJ_USER01, AC_USER01, AD_USER01 → siteb_pii_full.tar.gz |
| LMS_MIS sensitive tables | Library PII (DLIDB3), access-control data (Membership_new) → lms_mis_sensitive.tar.gz |
| JANRO church / administrative DBs | digiwave, DEACONESS, kis_user01, 21 databases |
| NAS reports | oz70 9,577 reports from [Victim A-NAS]; ~63 TB remaining on the volume |
| Chat DB (xim) | 6,807 users, 18,105 messages, 2,585 attachments |
| Other | Mail (xclickr31_[Victim A]), 6,874 login accounts |
Identification of [Victim A] and Web Shell Upload
login_results_v3.json recorded 197 login attempts against South Korean churches, including [Victim A]'s mis.[Victim A].com.
Figure 3. login_results_v3.json identifying mis.[Victim A].com among church login targets
HANDOVER_REPORT.md records that codex_x.aspx was uploaded to D:\[ERP]\[Victim A]_WK and ran as iis apppool\[Victim A]_wk. As of 9 September 2026, the shell was still reachable from the internet.
Figure 4. Operator notes on the WAS2 web shell at codex_x.aspx, including ws.sh / wssql.sh wrappers
Figure 5. WAS2 web-shell summary: URL, application-pool identity, and cmd / sql / file / info modes
Figure 6. codex_x.aspx still responding on mis.[Victim A].com at the time of analysis
Initial Lateral Movement and [ERP] Reverse Engineering
ws.sh sent a POST request to the web shell to run cmd.exe /c on WAS2 and scan 10.10.***.***/24. Identified hosts: WAS2 ERP ([Victim A-INT A-IP-1], public 114.200.***.***); WAS1 ([Victim A-INT A-IP-2], Replix/MCCS/BSR); IIS ([Victim A-INT A-IP-3]); MIS1 ([Victim A-INT A-IP-4], MSSQL/MariaDB/DB monitoring solution/ABB); MIS2 ([Victim A-INT A-IP-5]); NAS ([Victim A-INT A-IP-6]); nginx ([Victim A-INT A-IP-7], gw.[Victim A].com, RDP).
CREDENTIAL_AND_SYSTEMS.md records reverse engineering of [ERP] Security.dll (AES, DES, custom Base64). Decrypting ServerSetting.xml yielded MSSQL (MISV) sysadmin on four databases. xp_cmdshell was enabled, and the service account had SeImpersonate.
Figure 7. Operator notes on reversing [ERP] Security.dll (AES-256, DES, custom Base64)
Figure 8. Decrypted ServerSetting.xml MSSQL connection entries for MISV (credentials redacted)
Figure 9. MIS1 MSSQL summary: xp_cmdshell, sysadmin, and SeImpersonate
From MISV, linked-server reconnaissance identified JANRO ([Victim A-INT B-IP-1]), LMS_MIS ([Victim A-INT B-IP-2]), MIS ([Victim A-INT B-IP-3/4/5/6]), MariaDB ([Victim A-INT B-IP-7]), and an internal FTP host ([Victim A-INT B-IP-8], Insapic). JANRO, MIS, and LMS_MIS used remote_name=sa, so EXEC() AT [LINK] could run xp_cmdshell remotely via lq_cmd.sh / q.sh.
Figure 10. MISV linked servers JANRO, MIS, and LMS_MIS mapped as sa for remote xp_cmdshell
Figure 11. lq_cmd.sh and q.sh sending xp_cmdshell through codex_x.aspx
Secondary Lateral Movement with xp_cmdshell RCE
rce.sh used local xp_cmdshell to create a temporary SYSTEM service on a remote host. That path was used against the EFAM file server and MIS ([Victim A-INT A-IP-5]), then reused against MIS, LMS_MIS, and JANRO.
Figure 12. rce.sh creating a temporary SYSTEM service on a remote host via xp_cmdshell
Figure 13. Operator notes on SYSTEM RCE against the EFAM file server
On MIS, more than 40 databases were enumerated, including GJ_USER01 (members), AC_USER01 (accounting), and digiwave (access control).
Figure 14. MIS database inventory, including GJ_USER01, AC_USER01, and digiwave
A Base64-encoded DB monitoring solution master key (KS_SERVER.SERVER_MK) was recovered. KS_APPLIST listed DBA tools such as Toad/SQL Developer as monitoring targets.
Figure 15. DB monitoring solution master key and KS_APPLIST entries for DBA tools
LMS_MIS held about 41.2 GB of databases, including TB_ADMIN / userID and copies of GJ_USER01 / AC_USER01. 75 sensitive tables, including DLIDB3 and Membership_new, were packaged as lms_mis_sensitive.tar.gz.
Figure 16. LMS_MIS database sizes and privileged-account notes
Figure 17. LMS_MIS sensitive-table dump packaged as lms_mis_sensitive.tar.gz
JANRO, a development host, yielded full dumps of 21 databases, including kis_user01, digiwave, DEACONESS, and JANGRO.
Figure 18. JANRO inventory across 21 church and administrative databases
Internal FTP was reachable with the insapic account from MISV reconnaissance. GJ_Picture listed 60,891 resident-registration photos (SDNO.jpg).
Figure 19. Internal FTP GJ_Picture store of resident-registration photos (SDNO.jpg)
DB Monitoring Solution Bypass and MariaDB Root
The DB monitoring solution SecureFilter on port 5001 blocked dir V:\. SMB administrative shares \\127.0.0.1\V$ and \\127.0.0.1\W$ bypassed the filter. Volume V held MariaDB data (global_priv.MAD) and MSSQL files ([Victim A]_Primary.mdf 116 GB, log 430 GB). Volume W held MSSQL daily backups (xclickr31 ~23.7 GB; Common ~21.8 GB).
The hash in global_priv.MAD was cracked with SHA1(SHA1(password)). The recovered MariaDB root password matched the XIM / xclick administrator password.
Figure 20. DB monitoring solution UNC bypass, global_priv.MAD crack, and volumes V:/W:
NAS Access via Hardcoded Credentials
ws.sh against NAS ([Victim A-INT A-IP-6]) found a 5 July 2024 EXT backup with web.config and KakaoTalk API material, plus hardcoded NAS credentials. Matching credentials were also in the ABB agent's system-db.sqlite on MIS1.
From MIS1, net use could reach [Victim A-NAS] over SMB. The volume had about 63 TB remaining. DSM web login failed.
Figure 21. EXT backup on the NAS containing web.config and Kakao API material
Figure 22. Hardcoded NAS credentials in EXT web.config (values redacted)
Figure 23. ABB agent token used against the NAS backup share
Figure 24. Synology inventory for [Victim A-NAS], including [ERP]/oz70; about 63 TB remaining
Exfiltration through Pre-Positioned MinIO
Dumps from MIS / LMS_MIS / JANRO / FTP, V:/W: after the DB monitoring solution bypass, and NAS objects were staged on MIS1 at D:\export and uploaded to a previously compromised MinIO bucket.
79 major dumps, including GJ_USER01 and AC_USER01, were driven by siteb_pii_full.bat, which BCP-exported tables to D:\export, packed them as siteb_pii_full.tar.gz, and uploaded the archive to MinIO.
Figure 25. siteb_pii_full.bat BCP export of GJ_USER01 tables to D:\export
Figure 26. Upload of siteb_pii_full.tar.gz to the MinIO a-bucket
janro_gen.py generated janro_full2.bat for the same BCP-and-upload pattern against JANRO and kis_user01. janro_push2.py pushed that batch through the web shell.
Figure 27. janro_gen.py generating BCP commands and MinIO uploads for JANRO and kis_user01
Figure 28. janro_full2.bat BCP, tar, and MinIO PUT for janro_church_dbs.tar.gz and kis_erp_full.tar.gz
Figure 29. janro_push2.py pushing janro_full2.bat through the web shell in chunks
cloud_pull.py pulled the MinIO objects back onto the attacker server. cloud_pull.log recorded 69 retrieved files and 37 skips. 22 of those objects were still in [Victim A]_loot.
Figure 30. cloud_pull.py listing and downloading objects from MinIO into [Victim A]_loot
Figure 31. cloud_pull.log HTTP 200 results for member, payroll, and accounting TSV files
Figure 32. Recovered TSV sizes for member, payroll, and accounting tables
The same directory held NAS data from [ERP]\oz70.
Figure 33. OZ Report files from [ERP]\oz70 on the NAS
The cracked MariaDB password also unlocked xclick. xclickr31_user.tsv held 6,874 accounts. The exfiltrated data also included approximately 960,000 congregant records updated within the previous two years, including names and resident registration numbers. Related dumps include about 14,000 chats, 330,000 donation records, and 68,000 document-creation records.
Figure 34. xclickr31_user.tsv and related xclick components in the loot directory
Figure 35. Redacted xclick user rows, including names, teams, and email domains
Figure 36. Exported chat, approval, and donation dumps (~14,706 chats, ~68K approvals, ~331K donations)
[Victim B] Compromise and Data Exfiltration
[Victim B] was targeted before [Victim A]: groupware → SIMS → SAP → assets associated with the college ministry, GitHub, and Firebase.
| Technique | What was taken |
|---|---|
| SIMS UserInfoSearch (IDOR) | Arbitrary-user plaintext PIN, login ID, mobile, email |
| UserInfoManagementPasswordSave / UserInfoSave | Password reset/change on arbitrary accounts |
| SAP portal getEmpList / getPersonInfo | HR for 286 people (including the senior pastor) and 228 organization-tree entries |
| goPageSIMS / goPageSMART (SSO) | Authentication tokens for arbitrary employees |
| EKP bulletin board and approval APIs | 114 posts and 106 electronic-approval documents on gw.[Victim B].org |
| [Victim B]-univ API | Unauthenticated student/staff PII, QR ticket IDOR, leader mobile login |
| GitHub public-source review | 17 public repositories related to [Victim B] |
| Open Firebase | Storage allow read/write: if true; hardcoded DB and seed credentials |
| WAF bypass and credential reuse | All reused passwords expired or deleted; no successful login |
| Captured web context | Login, user-log, and SMART portal error screens |
Per-phase reports sat under pentest/[Victim B].
Figure 37. [Victim B] pentest reports covering groupware, SIMS, APIs associated with the college ministry, and WAF tests
Recon located subdomains, about 20 IPs, and core systems (Naver WAF, SAP, EKP, SIMS).
Figure 38. [Victim B] asset overview: SAP, EKP, SIMS, Exchange, and Naver WAF
result_.[Victim B].org_20260525_215444.xlsx lists older leaked credentials per subdomain. Groupware account hj*** was then used against EKP (gw.[Victim B].org) to call organizational-chart and employee APIs without authorization.
Figure 39. Leaked-credential spreadsheet highlighting gw.[Victim B].org EKP login for hj***
Figure 40. Operator notes on EKP employee-info APIs and electronic-approval IDOR tests
groupware_data.json and groupware_full.json contain records for 10 of 383 exfiltrated employees (empList).
Figure 41. Redacted groupware JSON with organization-tree and employee fields
On SIMS (sims.[Victim B].org), the same hj*** session was used to read other users' plaintext PINs through IDOR and then reset a manager-privileged account. In addition, personal information belonging to approximately 89,000 congregants was found among the exfiltrated data.
Figure 42. SIMS UserInfoSearch IDOR allowing plaintext PIN disclosure from a member session
Figure 43. SIMS UserInfoManagementPasswordSave / UserInfoSave password-reset chain
sims_special_accounts.json held 1,419 sensitive records.
Figure 44. SIMS JSON dumps, including sims_members_all.json and sims_special_accounts.json
Figure 45. Redacted SIMS special-account rows (emails and phone numbers)
Groupware SSO (goPageSMART) reached the SAP portal without a second login and yielded 286 HR records plus 96 employee photos.
Figure 46. SAP portal HR directory dump via groupware SSO (getEmpList / getPersonInfo)
Figure 47. Export of 96 employee photos from the SAP Content Server
Figure 48. employees_*.json and sap_hr_employees.json in the pentest directory
A total of 286 employee records were identified among the collected data.
Figure 49. Redacted employee JSON record (department and role fields)
Cookie files contained data from the initial member session and subsequently obtained sessions.
Figure 50. SIMS and SAP cookie files for member, manager, and admin sessions
The same directory held captured pages.
Figure 51. Captured SAP/groupware HTML pages and HR-dump scripts
Unauthenticated slug enumeration on [Victim B]-Univ univ-group-info returned staff names, phones, and bank-account fields. unashamed_univgroupinfo.json held eight such records.
Figure 52. Unauthenticated [Victim B]-Univ univ-group-info API returning staff PII and bank accounts
Figure 53. University API loot, including QR codes and unashamed_univgroupinfo.json
Firebase storage allowed unrestricted read and write (allow read/write: if true), with hardcoded database and seed credentials.
Figure 54. GitHub public-repo sync and open Firebase rules with hardcoded keys (redacted)
WAF-bypass and credential-reuse attempts failed; all reused passwords had expired or been deleted. Remaining notes include a 2016 OWA endpoint and a possible cppm subdomain-takeover risk.
Figure 55. Failed credential-reuse attempts across [Victim B] login portals
Figure 56. Operator follow-on notes: SQLi on a legacy ASP host, Exchange 2016 OWA, and cppm subdomain takeover
Conclusion
Neither case was a one-step intrusion. The [Victim A] compromise progressed from an ERP web shell to database administrator privileges, linked-server RCE, and MinIO staging. The [Victim B] compromise progressed from leaked credentials and IDOR to access across groupware, SIMS, SAP, and assets associated with the college ministry and Firebase.
The same operator had previously targeted a U.S. Christian content platform. MinIO administrator credentials from the U.S. compromise were reused to stage [Victim A] data, linking the two South Korean church intrusions to previously used infrastructure.
By using AI, attackers can rapidly carry out lateral movement, reverse engineering, vulnerability analysis, and data exfiltration. This can shorten the time between initial access and a broader compromise, leaving defenders less time to detect and contain an intrusion before it spreads across internal systems and exposes sensitive data.