Hackers breached two major South Korean churches, exposing more than one million congregant records and extensive financial and administrative data.
The investigation reveals how web shells, leaked credentials, and weak access controls opened routes into connected systems. In one case, attackers entered through a web shell planted in an enterprise resource planning, or ERP, system.
In the other, they used leaked credentials and insecure direct object reference, or IDOR, flaws in groupware and membership systems to reach sensitive records.
Analysts at OASIS identified the activity after examining files recovered from an attacker-controlled server. The evidence points to a multi-stage campaign involving database access, internal movement, and cloud staging, rather than a single malware strain.
OASIS said in a report shared with Cyber Security News (CSN) that the attackers collected records connected to congregants, donations, payroll, employee data, approval documents, chats, and identity information.
That is particularly concerning because community organizations can hold sensitive information that criminals could use for fraud or targeted scams. Unique-person totals remain unverified.
Hackers Breach Two Major South Korean Churches
Researchers collected files from an attacker server between August 28 and September 1, 2026. The U.S.-based server contained tooling, stolen data, and operator reports related to both victims.
The first intrusion involved a web shell in the church’s ERP system. Attackers reversed ERP application files, decrypted database settings, and obtained administrator access to Microsoft SQL Server.
They then used xp_cmdshell, a SQL Server feature that can launch operating-system commands, to move across linked systems.
That access opened member, accounting, access-control, library, chat, and mail databases. Attackers bypassed a database-monitoring control, recovered a MariaDB root password, and used hardcoded NAS credentials to reach backup storage.
Similar misuse has appeared in SQL Server attack investigations, where a database becomes a route to the underlying Windows host.
The collection contained about 960,000 congregant records updated in the previous two years, including names and resident registration numbers.
![Exfiltrated [Victim A] dumps in [Victim A]_loot (Source - OASIS)](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhPYgfLTItB2AYnbG3q5z0mG3KAauY-JYU6WTVU4-QvwgR65jjAJiZbvhrDa8cTNlhUtkBdA-P8elnw1TkNJk_jDdQGVFDEPnPKS922O4lwUtTrkGdRldFMfB7hpNDt9UAjLZorxFqopP3TYLVffdpoP1-0zSMFEtc6XGQcoIytZNZbPFbYtRsl-SVsqbo/s1600/Exfiltrated%20%5BVictim%20A%5D%20dumps%20in%20%5BVictim%20A%5D_loot%20(Source%20-%20OASIS).webp)
It also included roughly 330,000 donation records, 68,000 document-creation records, more than 14,000 chats, and 6,874 login accounts. Researchers recovered 47.3 GB across 13,939 files from a compromised MinIO bucket used to stage the data.
The second church was targeted earlier through leaked credentials, groupware, and IDOR weaknesses in EKP and SIMS services. An IDOR flaw occurs when an application accepts a user-controlled record reference but fails to confirm the requester is allowed to access it.
The issue resembles the unauthenticated API data exposure reported in another faith-related service. Using a member session, attackers viewed other users’ plaintext PINs and reset a manager-privileged account.
They accessed about 89,000 congregant records, 383 employee records, 286 human-resources entries, 96 employee photos, and approval documents. The investigation also found exposed college-ministry APIs and cloud storage configured for unrestricted read and write access.
How Defenders Can Respond
Neither intrusion was a one-step event. The first progressed from internet-facing application access to database administration, remote command execution, network storage, and off-site staging.
The second turned leaked credentials and missing authorization checks into access across groupware, SIMS, SAP, and connected services.
Organizations should remove unauthorized web shells, rotate exposed passwords and tokens, and invalidate active sessions. They should inspect ERP, database, NAS, and cloud logs for unusual access, large exports, or connections to the infrastructure listed below.
Credentials found in backups, application settings, public code, or exposed storage should be treated as compromised. Administrators should disable xp_cmdshell where it is not essential, restrict linked-server privileges, and segment database systems.
Teams should investigate suspicious command execution under SQL Server service accounts, particularly activity reaching other internal hosts. For web applications, every request must verify both identity and permission to access the requested record.
Authorization testing, least privilege, and safer password-reset functions can prevent IDOR chains like this one. Earlier IDOR vulnerability mitigation coverage stresses patching, auditing sensitive changes, and rotating service credentials.
The report warns that AI can accelerate reverse engineering, vulnerability research, lateral movement, and exfiltration. Faster attacker workflows give defenders less time to detect and contain intrusions before sensitive data leaves internal systems.
Indicators and investigation artifacts below reproduce the source values exactly. Redacted addresses are not actionable indicators, and legitimate files require contextual investigation rather than automatic blocking. No literal file-hash values were published.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| IPv4 address | 192.3.239.164 | U.S.-located attacker server from which researchers collected tooling and stolen material. |
| Redacted network | 10.10.***.***/24 | Internal network scanned through the first church’s web shell; incomplete source value. |
| Redacted IPv4 address | 114.200.***.*** | Public address associated with the first church’s ERP host; incomplete source value. |
| Redacted domain | mis.[Victim A].com | First church’s ERP target and web-shell location; victim identity withheld. |
| Redacted domain | gw.[Victim A].com | First church’s groupware-related host identified during reconnaissance. |
| Redacted domain | gw.[Victim B].org | Second church’s EKP groupware target. |
| Redacted domain | sims.[Victim B].org | Second church’s SIMS service affected by authorization weaknesses. |
| Web-shell filename | codex_x.aspx | Malicious ERP web shell; reportedly still reachable on September 9, 2026. |
| File artifact | login_results_v3.json | Recorded 197 login attempts against South Korean churches. |
| Operator report | HANDOVER_REPORT.md | Documented web-shell deployment and execution context. |
| Operator report | CREDENTIAL_AND_SYSTEMS.md | Documented application reverse engineering and recovered database access. |
| Attack script | ws.sh | Wrapper used to send commands through the web shell. |
| Attack script | wssql.sh | SQL-related web-shell wrapper referenced in operator notes. |
| Attack script | lq_cmd.sh | Used for command execution through linked SQL servers. |
| Attack script | q.sh | Used alongside linked-server command execution. |
| Attack script | rce.sh | Created temporary remote services for SYSTEM-level execution. |
| Application artifact | Security.dll | Legitimate ERP library reverse engineered to recover configuration secrets. |
| Configuration artifact | ServerSetting.xml | Decrypted ERP configuration yielded database administrator access. |
| Database artifact | global_priv.MAD | MariaDB privilege data used to recover the root password; no literal hash published. |
| Local administrative share | \\127.0.0.1\V$ | Loopback SMB share used to bypass a local-volume monitoring restriction; not attacker infrastructure. |
| Local administrative share | \\127.0.0.1\W$ | Additional loopback SMB share used in the monitoring bypass. |
| Database artifact | [Victim A]_Primary.mdf | Legitimate MSSQL data file identified on the accessed volume; victim name redacted. |
| Configuration artifact | web.config | Backup configuration contained hardcoded NAS credentials. |
| Backup-agent artifact | system-db.sqlite | Contained matching NAS access credentials. |
| Redacted deployment path | D:\[ERP]\[Victim A]_WK | ERP directory where the web shell was uploaded. |
| Staging directory | D:\export | Local directory used to stage exported data before uploading it. |
| Redacted loot directory | [Victim A]_loot | Attacker-side directory containing first-church dumps, tools, and reports. |
| Redacted loot directory | pentest/[Victim B] | Attacker-side directory containing second-church collections and reports. |
| Exfiltration script | siteb_pii_full.bat | Exported sensitive database tables, packaged them, and uploaded the archive. |
| Stolen-data archive | siteb_pii_full.tar.gz | Archive containing administrative and personal-information exports. |
| Stolen-data archive | lms_mis_sensitive.tar.gz | Archive containing 75 sensitive tables from a linked system. |
| Attack script | janro_gen.py | Generated database-export and upload commands. |
| Attack script | janro_full2.bat | Batch file performing database exports, archive creation, and uploads. |
| Attack script | janro_push2.py | Transferred the generated batch file through the web shell. |
| Stolen-data archive | janro_church_dbs.tar.gz | Archive of church-related database exports. |
| Stolen-data archive | kis_erp_full.tar.gz | Archive of ERP database exports. |
| Retrieval script | cloud_pull.py | Downloaded staged MinIO objects onto the attacker server. |
| Retrieval log | cloud_pull.log | Recorded 69 retrieved files and 37 skipped objects. |
| Storage bucket | a-bucket | MinIO bucket referenced in the stolen-data upload workflow. |
| Stolen-data file | xclickr31_user.tsv | Export containing 6,874 login accounts. |
| Photo filename pattern | SDNO.jpg | Legitimate photo naming pattern in the accessed resident-registration photo store. |
| Redacted credential file | result_.[Victim B].org_20260525_215444.xlsx | Spreadsheet containing previously leaked credentials by subdomain. |
| Stolen-data file | groupware_data.json | Recovered employee and organizational information. |
| Stolen-data file | groupware_full.json | Additional recovered groupware employee information. |
| Stolen-data file | sims_members_all.json | SIMS membership export referenced in the recovered collection. |
| Stolen-data file | sims_special_accounts.json | Contained 1,419 sensitive account records. |
| Stolen-data filename pattern | employees_*.json | Employee JSON exports found in the attacker directory. |
| Stolen-data file | sap_hr_employees.json | SAP human-resources employee export. |
| Stolen-data file | unashamed_univgroupinfo.json | Contained eight college-ministry records with personal and bank-account fields. |
| Execution artifact | cmd.exe | Legitimate Windows command interpreter invoked through the web shell; suspicious only in context. |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
