Undercode Successfully Recovers 8 Years of Data After Unknown Cloud Ransomware Attack Targeting Saudi Dates Company

Listen to this Post

Forensic Investigation Reveals External NTLM Intrusion, IIS Web Shell Deployment, Log Manipulation, and Full Data Recovery Operation

By Undercode Security Research
Incident ID: INC-2026-0123

Executive Summary

Undercode Security has successfully completed a complex digital recovery and forensic investigation after a Saudi-based dates company suffered a catastrophic data-loss incident affecting nearly 8 years of critical business records.

The incident involved a previously unidentified ransomware strain combined with cloud-based encryption behavior, unauthorized remote access, and post-compromise activity designed to maintain persistence and hide attacker operations.

Unlike traditional ransomware cases where attackers only encrypt files, this incident demonstrated a multi-stage intrusion:

  1. External credential attacks against exposed services.
  2. Successful NTLM authentication.
  3. IIS server compromise.
  4. Web shell deployment.
  5. Privileged execution through application services.
  6. Security log manipulation.
  7. Data encryption and operational disruption.

Through forensic reconstruction and recovery procedures, Undercode restored access to critical business data without relying on attacker decryption keys.

Attack Timeline Reconstruction

Phase 1 — External Authentication Campaign

The investigation identified a large number of failed authentication attempts against Windows accounts.

The attackers used external network authentication attempts targeting:

  • Administrator accounts
  • Service accounts
  • Existing business usernames

Observed Windows Security Events:

Event IDMeaning
4625Failed authentication attempts
4624Successful authentication
4740Account lockout
1102Security log cleared

The pattern indicates automated credential attacks rather than manual login attempts.

Confirmed Successful Intrusion

Successful Authentication Source

The investigation identified:

185.59.73.99

as the IP address associated with the successful authentication event.

Observed:

Event ID: 4624
Logon Type: 3 (Network)
Authentication: NTLM
Account Targeted:
Administrator / Local Accounts

The IP address should be considered an attack infrastructure indicator, not definitive proof of attacker nationality.

Threat actors frequently operate through:

  • VPS infrastructure
  • Proxy networks
  • Compromised servers
  • VPN services
  • Cloud providers

Attack Infrastructure Indicators

Observed Source Addresses

IP AddressActivity
185.59.xx.99Successful authentication
157.66.xxx.139Failed password attempts
223.84.xxx.194Invalid usernames
43.166.xxx.25Administrator targeting
129.226.xxx.94Administrator targeting
45.194.xx.237Failed authentication

Technical Investigation

How The Attack Happened (High-Level)

The attack chain followed a common modern intrusion pattern:

Internet Exposure
        |
        ↓
NTLM Authentication Abuse
        |
        ↓
Valid Account Access
        |
        ↓
IIS Application Compromise
        |
        ↓
Web Shell Persistence
        |
        ↓
Privilege Expansion
        |
        ↓
Data Encryption
        |
        ↓
Recovery Operation

IIS Persistence Discovery

During forensic analysis, Undercode discovered a malicious web shell hidden inside a legitimate application directory:

C:\inetpub\wwwroot\SMACCOnline\
3SCartAPI\
381dYioyz5.JhDt7Ahx

File hash:

SHA256:
f274ca4c8b72cef7c92b30c5b033a275304bf556f14a5640a059b2d40e0576e2

The attacker abused IIS configuration by modifying application execution settings.

Observed affected components:

smacc
smaccweb

The attacker configured IIS application execution under administrative privileges, allowing malicious code execution through the web environment.

Living-Off-The-Land Techniques

The investigation found abuse of legitimate software components.

Example:

OpenSSL 3.0.9

The tool itself is legitimate.

However, attackers commonly abuse trusted software to:

  • Generate certificates
  • Encrypt communication
  • Hide malicious traffic
  • Blend with normal administration activity

This technique is known as:

Living Off The Land (LOTL)

Log Manipulation & Anti-Forensics

Undercode identified evidence of security log clearing:

Event ID: 1102

The Windows Security Audit Log was cleared using an administrative account.

Purpose:

  • Remove authentication evidence
  • Hide attacker activity
  • Delay investigation

However, remaining artifacts allowed reconstruction of the attack timeline.

Data Recovery Operation

The affected environment contained approximately:

  • 8 years of company data
  • Business records
  • Operational databases
  • Critical documents

Recovery involved:

  • Disk-level forensic analysis
  • File system reconstruction
  • Malware artifact removal
  • Timeline correlation
  • Integrity verification

Undercode successfully recovered the affected data and restored business continuity.

Fact Checker ✅

Many ransomware incidents involve only encryption. However, modern groups increasingly combine:

  • Data theft
  • Credential abuse
  • Cloud access
  • Extortion

Undercode Threat Prediction 🔮

Based on this incident, Undercode predicts:

1. More Hybrid Ransomware Attacks

Future ransomware campaigns will increasingly combine:

  • Credential attacks
  • Cloud abuse
  • API compromise
  • Identity theft

2. IIS Servers Will Remain High-Value Targets

Organizations running:

  • Public websites
  • ERP systems
  • Custom business applications

should expect continued targeting.

3. Recovery Will Become A Competitive Advantage

Organizations with:

  • Offline backups
  • Immutable storage
  • Tested recovery procedures

will recover faster than organizations focused only on prevention.

Security Recommendations

✅ Disable unnecessary internet exposure
✅ Restrict NTLM authentication
✅ Enforce MFA everywhere
✅ Monitor privileged accounts
✅ Protect backup systems from ransomware access
✅ Perform regular incident response testing
✅ Deploy endpoint detection and response solutions

Final Statement

This incident demonstrates that ransomware defense is no longer only about preventing encryption.

Modern attacks combine:

Identity compromise + persistence + stealth + encryption.

Undercode’s investigation successfully transformed a major data-loss incident into a complete forensic understanding of attacker behavior and a successful recovery operation.

Reported by Undercode Technologies Ltd
Security Research & Incident Response Division
https://undercode.co.uk

More infos: [email protected]