Executive Summary
Two open directories hosted on a Singapore VPS (69.48.228[.]86) have exposed an extensive multi-target campaign operated by a Chinese-speaking threat actor identified by the alias 'Miku'. The operator utilized a unified infrastructure of rotating SOCKS5 proxies and Chisel-based tunneling to conduct six parallel operations, ranging from financial fraud to high-level strategic reconnaissance.
The technical workflow included mass scanning of 'New API' LLM gateways using forged Stripe webhooks, LLM-assisted mapping of Vietnamese government and military hierarchies, and credential spraying against Pakistani defense education portals. A successful breach of a Mexican billing platform was also documented, involving cleartext credential extraction via SQL injection and the deployment of JSP web shells for persistence.
This campaign highlights the increasing convergence of traditional exploitation techniques with AI-assisted target classification and fraud automation. The actor's interest in data-center liquid-cooling supply chains suggests a specific focus on critical infrastructure and emerging technology sectors, necessitating urgent patching of public-facing CMS platforms and monitoring for unauthorized reverse tunneling infrastructure.
Key Details
Threat Name
Miku Global Multi-Target Campaign
Affects
BuddyBoss Platform, WordPress
Adversary
Miku Other Adversaries and Aliases: SideWinder
Malware/Tools
chisel, exec_shell.jsp, fscan, OneForAll, sqlmap, nuclei, Havoc
