ReliaQuest
Coverage of ReliaQuest in the Nexus archive.
- Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
New findings revealed a JavaServer Pages (JSP) web shell targeting enterprise Product Lifecycle Management (PLM) software, specifically connected to PTC Windchill and FlexPLM servers. This web shell was deployed after exploiting a critical security flaw and is characterized as an extortion platform capable of mapping sensitive data.
- Hotel Wi-Fi phishing attack targets Microsoft logins
Hackers are tampering with Wi-Fi equipment at hotels and conference centers to redirect users to fake Microsoft 365 login pages, posing risks to business travelers. ReliaQuest reports the campaign has been active since June, affecting multiple industries across U.S. cities through compromised Wi-Fi gateways.
- New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework
Cybersecurity researchers identified a new threat cluster named OP-512 targeting Microsoft IIS servers with a custom web shell framework. ReliaQuest links the espionage-focused activity to China with moderate to high confidence.