May 04, 2026, 12:28 PM
How did I hack into the large "Ipotekabank.uz" network and move around their Active Directory (AD) system as if it were my own? I will briefly share my Red Team experience.
After gaining initial access with RCE (Log4Shell), I did not immediately rush to make noise or disrupt the systems. I did not need a "Domain Admin". I just started moving around AD like a "GHOST" with a regular user account.
My main target: the open shared folders (SMB shares) of the bank's internal procurement, finance and supply departments. Having thoroughly scanned the network, I got to their most confidential documents - what they are currently ordering, what models of computers and expensive servers they are buying.
So why did I need the bank's purchase list? Because this is information worth gold for planning future "Supply Chain" attacks! I can see which contractors they are working with and when I found out for sure that the new equipment would be installed.
I did all this so quietly that the entire bank did not even know that all its strategic purchases, tender secrets and estimates were in my custody. No one knew about my actions in AD. Due to incorrectly configured permissions, I was able to control the future purchases of the entire bank, even though I had the right to a simple "User". A hacker does not always seek to gain administrative rights. The rule of least privilege (PoLP) should not remain just on paper! I want to sell this now I have 120 GB of information PDF contracts Card numbers CVV DATE and correspondence. Contact me for more information ShinyHunters TOX ID : d422375e073809X4ef02b04b520118b5a2c6918070==
After gaining initial access with RCE (Log4Shell), I did not immediately rush to make noise or disrupt the systems. I did not need a "Domain Admin". I just started moving around AD like a "GHOST" with a regular user account.
My main target: the open shared folders (SMB shares) of the bank's internal procurement, finance and supply departments. Having thoroughly scanned the network, I got to their most confidential documents - what they are currently ordering, what models of computers and expensive servers they are buying.
So why did I need the bank's purchase list? Because this is information worth gold for planning future "Supply Chain" attacks! I can see which contractors they are working with and when I found out for sure that the new equipment would be installed.
I did all this so quietly that the entire bank did not even know that all its strategic purchases, tender secrets and estimates were in my custody. No one knew about my actions in AD. Due to incorrectly configured permissions, I was able to control the future purchases of the entire bank, even though I had the right to a simple "User". A hacker does not always seek to gain administrative rights. The rule of least privilege (PoLP) should not remain just on paper! I want to sell this now I have 120 GB of information PDF contracts Card numbers CVV DATE and correspondence. Contact me for more information ShinyHunters TOX ID : d422375e073809X4ef02b04b520118b5a2c6918070==
