Release validation: tests green, USB pack, fleet UX and API hardening.
Some checks failed
CI Docker Mining Proof / Linux agent hashrate proof (push) Has been cancelled
Some checks failed
CI Docker Mining Proof / Linux agent hashrate proof (push) Has been cancelled
Fix macOS agent cross-compile (SilentAVExclusion) and Calibrate E2E nav selector; expand tests and docs; refresh portable usb binary and spread/wiki assets.
This commit is contained in:
@@ -1,5 +1,7 @@
|
||||
# Web-Mediated Spread Techniques (Research Summary)
|
||||
|
||||
> **Operator playbook (tabbed HTML):** [SPREAD_TECHNIQUES.html](SPREAD_TECHNIQUES.html) — step-by-step Emberwake how-tos. This file is the research matrix.
|
||||
|
||||
> **Scope:** Documented red-team / threat-intelligence vectors mapped to AetherForge capabilities. For **authorized** penetration testing, lab environments, and defensive planning only. Sources cited below; landscape as of **2024–2026**.
|
||||
|
||||
---
|
||||
@@ -24,7 +26,7 @@
|
||||
|
||||
| Technique | Feasibility | Detection risk | AetherForge mapping |
|
||||
|-----------|-------------|----------------|---------------------|
|
||||
| **Dropper landing page** — button/link → `/get` or spread-kit ZIP | **Easy** | Med (URL reputation, TLS logs) | **Has:** `/get`, `/install.ps1`, `/install.sh`, `?pin=`, `?c=` campaign tags. **Needs:** `spread-kit-web-publisher` static templates (API exists; templates missing). |
|
||||
| **Dropper landing page** — button/link → `/get` or spread-kit ZIP | **Easy** | Med (URL reputation, TLS logs) | **Has:** `/get`, `/install.ps1`, `/install.sh`, `?pin=`, `?c=`; static kit at `spread-kit-web-publisher/` + `/spread/`; ZIP export via `POST /api/v1/builder/spread-kit-export`. |
|
||||
| **curl \| bash / `irm \| iex` docs page** — install instructions for servers | **Easy** | Med (EDR script block, proxy logs) | **Has:** `install.sh` / `install.ps1` with UA-aware `/get`, campaign env (`AETHER_CAMPAIGN`). Pin build via `?pin={build_id}`. |
|
||||
| **Fake browser / app update page** (SocGholish pattern) | **Medium** | High (browser update lures heavily signatured) | **Has:** dropper + spread-kit launchers. **Needs:** branded HTML lander, geo/UA gate, optional TDS. See [Trend Micro SocGholish](https://www.trendmicro.com/en/research/25/c/socgholishs-intrusion-techniques-facilitate-distribution-of-rans.html). |
|
||||
| **JS redirect / referrer gate** (search → your lander) | **Medium** | Med–High (injected-script hunting) | **Needs:** fingerprint JS in web-publisher kit; **Has:** campaign tracking on final fetch. [JSFireTruck](https://unit42.paloaltonetworks.com/malicious-javascript-using-jsfiretruck-as-obfuscation/) scale shows pattern is alive but noisy. |
|
||||
@@ -80,12 +82,10 @@
|
||||
|
||||
| Gap | Emberwake / web-publisher role |
|
||||
|-----|-------------------------------|
|
||||
| `spread-kit-web-publisher/` templates **missing** | Static site ZIP export via `POST /api/v1/builder/spread-kit-export` (404 today) |
|
||||
| Emberwake **UI tab** not in web app | Notes + campaign API exist server-side only |
|
||||
| No **fake-update** HTML kit | SocGholish-style lander |
|
||||
| No **fake-update** HTML kit | SocGholish-style lander — operator supplies branding |
|
||||
| No **JS fingerprint / TDS** gate | Filter bots, mobile, non-target geo before showing download |
|
||||
| No **OAuth redirect** helper | Entra app registration docs only |
|
||||
| No **package registry** publish | npm/PyPI/Docker supply chain out of scope for forge |
|
||||
| No **public registry** publish | npm/PyPI typosquat out of scope — use `npm-helper-export` on registries you own |
|
||||
|
||||
---
|
||||
|
||||
|
||||
Reference in New Issue
Block a user