Normal view

There are new articles available, click to refresh the page.
Today — 23 July 2026Main stream

Olympic Mountain Glory

23 July 2026 at 00:01
The Olympic Peninsula, viewed at an angle from above, features snow-capped mountains surrounded by deep, forested river valleys. Islands in Puget Sound and developed areas including Seattle and Tacoma appear across the top of the photo.
May 6, 2016

Alpine glaciers, wild coastlines, temperate rainforests, and deep river valleys coexist on the Olympic Peninsula in the northwest corner of Washington state. Surrounded by blue waters, peaceful islands, and bustling population centers, its rugged interior remains a relatively remote bastion of wilderness.

The Olympic Mountains’ imposing terrain comes into focus in this oblique view of the region, captured by an astronaut aboard the International Space Station. The image is a composite, made of several sequential, overlapping photos fused together into a panorama. Olympic National Park encompasses the peninsula’s mountainous core, along with some stretches of the Pacific coastline. Much of the remaining area is either national forest, state-owned land, or tribal territory.

The rock making up the mountains mostly originated beneath the surface of the ocean. From about 55 to 15 million years ago, layers of basalt from undersea eruptions and sand and mud transported seaward by rivers accumulated on the ocean bottom. This material was scraped off the Juan de Fuca plate as it subducted beneath the North American plate, with rock layers crumpling and rising up to 8,000 feet (2,440 meters) above sea level.

Tectonic forces continue to push the mountains skyward, but the countervailing force of erosion in this rainy, snowy corner of the country effectively cancels out the uplift. Snow at higher elevations feeds glaciers that carve out underlying rock. Glaciers in the Olympics are retreating and thinning, however, and their numbers are declining. One study tallied 255 glaciers and perennial snowfields in the range in 2015 and found that 35 glaciers and 16 perennial snowfields had disappeared in the preceding 35 years.

Other erosion is evidenced by the deep valleys radiating out from the snowy peaks. The Hoh, Queets, and Quinault rivers, draining west into the Pacific Ocean (bottom of the frame), are prominent in this view. These verdant valleys are known for their temperate rainforests, and the ancient forest in the Hoh River valley was once considered among the most naturally quiet places in the U.S., uninterrupted by human-caused noise.

Flowing to the north, the Elwha River has a rich natural and human history, including some of the earliest Euro-American exploration of the Olympics. Sponsored by a Seattle newspaper, an expedition from December 1889 to May 1890 crossed the mountain range from north to south, traveling up the Elwha valley and down the Quinault. The party spent several months in the Elwha Valley, their progress hindered by an unusually harsh and snowy winter. 

In the early 1900s, entrepreneurs saw economic opportunity in the valley. Two dams constructed on the river produced power for local industry. But the structures came with costs, such as blocking the migration of once-abundant trout and salmon to their spawning grounds. In 2011 and 2014, the dams were removed in what was then the largest such project in the U.S., and the process of restoring fish populations, seeding native plant communities, and replenishing sediment along the riverbanks commenced.

The mouth of the Elwha forms a delta in the Strait of Juan de Fuca, the waterway bordering the peninsula to the north. The U.S.-Canada border runs through the middle of this 11- to 17-mile-wide (18- to 27-kilometer-wide) channel, with Vancouver Island in British Columbia lying to the north. The strait connects the Pacific Ocean with the Strait of Georgia and Puget Sound. Ship traffic uses the strait to access important West Coast ports, including Seattle and Tacoma, visible along the top-right edge of the image.

Astronaut photographs ISS047-E-104138 through ISS047-E-104144 were acquired on May 6, 2016, with a Nikon D4 digital camera using a focal length of 400 millimeters. They are provided by the ISS Crew Earth Observations Facility and the Earth Science and Remote Sensing Unit at NASA Johnson Space Center. The images were taken by a member of the Expedition 47 crew. The images have been cropped and enhanced to improve contrast, and lens artifacts have been removed. The International Space Station Program supports the laboratory as part of the ISS National Lab to help astronauts take pictures of Earth that will be of the greatest value to scientists and the public, and to make those images freely available on the Internet. Additional images taken by astronauts and cosmonauts can be viewed at the NASA/JSC Gateway to Astronaut Photography of Earth. Story by Lindsey Doermann.

Downloads

The Olympic Peninsula, viewed at an angle from above, features snow-capped mountains surrounded by deep, forested river valleys. Islands in Puget Sound and developed areas including Seattle and Tacoma appear across the top of the photo.

May 6, 2016

JPEG (18.26 MB)

References & Resources

The Olympic Peninsula, viewed at an angle from above, features snow-capped mountains surrounded by deep, forested river valleys. Islands in Puget Sound and developed areas including Seattle and Tacoma appear across the top of the photo.

You may also be interested in:

Stay up-to-date with the latest content from NASA as we explore the universe and discover more about our home planet.

Belts of Green in the Washington Suburbs

3 min read

Along the northeast side of the Capital Beltway in Maryland, green spaces weave through the developed landscape.

Article

Colonial National Historical Park

2 min read

The colonial communities of “America’s historic triangle” played defining roles in the road to American independence.

Article

Great Balls of Fire

4 min read

An astronaut on the International Space Station was surprised to photograph a shower of light streaking through the darkness while…

Article
Before yesterdayMain stream

Fans of the Arctic

14 July 2026 at 00:01
A braided river meanders across the image. Smaller streams empty into the wide channel from either side, forming fan-shaped deposits.
Alluvial fans form along a braided river channel on Severny Island in the Russian Arctic in an image acquired on August 1, 2025, by the OLI (Operational Land Imager) on Landsat 9.
NASA Earth Observatory/Lauren Dauphin

Editor’s Note: Today’s story is the answer to the July Puzzler.

Call it an alluvial face-off. On the southern end of Severny Island in the Russian Arctic, rivers rush down from rugged terrain flanking a broad valley. Upon reaching flatter ground, the waters slow and distribute sediment into cone-shaped features called alluvial fans. Several appear in opposing orientations alongside a braided river in this Landsat 9 image.

Severny Island (Ostrov Severnyy) is a mountainous, uninhabited landmass in the frigid high latitudes of the Northern Hemisphere. Part of the Novaya Zemlya archipelago, the island is largely covered in glacial ice. Some glaciers, especially in the north, terminate in the sea, while others end on land, feeding meltwater into glacial streams.

Sediment-laden streams, along with the island’s topography, create favorable conditions for the formation of alluvial fans. The features typically appear at the base of steep mountain ranges, where narrow river channels open onto flatter terrain. There, rivers can slow, divide into smaller channels, and deposit sediment. Over time, the channels migrate back and forth to build up fan-shaped deposits. Dueling fans line several northwest-southeast-trending valleys in the wider view below.

Ice-capped mountains are interrupted by broad valleys lined with alluvial fans.
A wide view of southern Severny Island in the Russian Arctic shows ice-capped mountains interrupted by broad valleys lined with alluvial fans. The image was acquired on August 1, 2025, by the OLI (Operational Land Imager) on Landsat 9.
NASA Earth Observatory/Lauren Dauphin

Seasonal snowmelt and glacial runoff likely keep Severny’s rivers supplied with ample fan-building material. Hydrologists note that higher river flows during the warmer months, driven by snowmelt, can carry more sediment out of the mountains. Glaciers also produce large volumes of eroded material as they grind downslope, some of which flushes out in meltwater.

Smaller, land-terminating mountain glaciers, like those on southern Severny Island, are particularly prone to melting as the atmosphere warms. Severny’s ice is relatively understudied due to its remoteness, but satellite observations give scientists an understanding of its health. Recent analyses incorporating digital elevation models found that land-terminating glaciers across the Novaya Zemlya archipelago thinned during the 2000s and 2010s, especially at lower elevations.

NASA Earth Observatory images by Lauren Dauphin, using Landsat data from the U.S. Geological Survey. Story by Lindsey Doermann.

Downloads

A braided river meanders across the image. Smaller streams empty into the wide channel from either side, forming fan-shaped deposits.

August 1, 2025

JPEG (19.56 MB)

References & Resources

You may also be interested in:

Stay up-to-date with the latest content from NASA as we explore the universe and discover more about our home planet.

Cañon Fiord’s Whirling Waters

3 min read

During the 2022 summer melt season, sediment plumes and fractured sea ice traced swirling eddies in a branch of the…

Article

A Sea of Spinning Clouds

3 min read

Icy, isolated Peter I Island stirred up a show in the atmosphere off the West Antarctic coast.

Article

Signs of Thaw in the Bering Sea

3 min read

Drifting sea ice fragments near Alaska’s Saint Lawrence and Nunivak islands and colorful water around the Yukon Delta heralded the…

Article

Wild, Scenic, and Increasingly Rusty

13 July 2026 at 00:01
A map of Alaska shows rusting river locations, with red colors indicating higher density. Most have been observed in the Brooks Range, stretching east-west across northern Alaska.
Rusting rivers occur across the Brooks Range in northern Alaska, as shown in this map based on in situ and satellite observations from 2007-2024.
NASA Earth Observatory/Michala Garrison

From declines in annual sea ice extent to the greening of the tundra, environmental change has been unfolding incrementally in the Arctic over decades. Some shifts, however, have come on more abruptly.

Satellite, aerial, and ground-based surveys spanning more than 600 miles (1,000 kilometers) across Alaska’s Brooks Range have observed stream water changing from clear to orange in more than 200 watersheds. What’s more, scientists are finding that the switch has largely taken place within the past 10 to 12 years, coinciding with a pronounced increase in air and ground temperatures.

Thawing permafrost soils, accelerated by warming air and ground temperatures, are the most likely cause of the “rusty” rivers, scientists say. They surmise that water is now encountering thawed ground and bedrock where it previously had not. Chemical weathering of minerals leaches iron, sulfuric acid, and trace metals into streams, akin to the process behind acid mine drainage, which similarly pollutes and discolors water near abandoned mines. Microbes may also contribute to the color change by producing a soluble form of iron as they digest plant and animal matter in thawing soils, which then becomes oxygenated, or “rusts,” in flowing streams.

Researchers have only recently begun to comprehend the prevalence of rusting rivers in Arctic regions. In 2024, a team of National Park Service, U.S. Geological Survey, and university scientists documented 75 northern Alaskan streams that recently changed from clear to orange. With subsequent exploration, mostly using high-resolution satellite imagery, they added 200 more observations. The locations of these discolored streams, published in NOAA’s 2025 Arctic Report Card, are shown in the map above.

“I’m still surprised by the broad spatial scope of our observations,” said Brett Poulin, environmental toxicologist at the University of California, Davis. He and his collaborators have been monitoring the region’s streams since 2013—when many were still clear. “Now we’re seeing hundreds of streams that have changed color seemingly overnight, including in designated National Wild & Scenic River corridors,” he said.




2017
2020

A gently curving river runs from right to left through green tundra vegetation.
NASA Earth Observatory/Michala Garrison

A gently curving river runs from right to left through green tundra vegetation. A segment of the river appears orange.
NASA Earth Observatory/Michala Garrison

A gently curving river runs from right to left through green tundra vegetation.
NASA Earth Observatory/Michala Garrison
A gently curving river runs from right to left through green tundra vegetation. A segment of the river appears orange.
NASA Earth Observatory/Michala Garrison

2017

2020


The Agashashok River in Noatak National Preserve is one of many streams in Alaska whose water has turned from clear to rusty orange. The change appears in these images, acquired on July 12, 2017 (left), and July 20, 2020 (right), by the OLI (Operational Land Imager) on Landsat 8. NASA Earth Observatory images by Michala Garrison.

Observations from NASA/USGS Landsat satellites allowed the team to determine the timing of several of these changes. For the 2024 study led by ecologist Jon O’Donnell of the National Park Service, the team calculated a redness index based on red and blue spectral information sensitive to the color of iron hydroxides (i.e., rust) in water. After analyzing a subset of streams, they found that some turned rusty around 2018 and stayed that way, while others had periods of rusting and then returned to being clear.

One stream that underwent a sudden change is the Agashashok River in Noatak National Preserve (above). In 2019, a jump in redness values appeared in Landsat data along this waterway. Ground and aerial surveys the same year found an orange section of the river several kilometers long, and vegetation around nearby groundwater seeps and springs appeared blackened. “The Landsat archive has proved uniquely useful for investigating the historical onset of rusting rivers where creeks and rivers are sufficiently large,” Poulin said.

Having gained a better picture of the extent and timing of the phenomenon, the researchers want to focus on the conditions driving the orange color’s onset and the yearly and seasonal changes. A deep snowpack may play a role some years, for example, by insulating the soil from cold winter temperatures and enabling permafrost thaw earlier in the summer. In addition, periods of higher streamflow throughout the year can dilute the discoloration. The team is planning a geophysical survey along a hillslope where acidic groundwater is discharging to the surface to investigate the subsurface geology, hydrology, and permafrost.

Further, they seek to quantify the effects on water quality and aquatic ecosystems. Communities rely on these river systems for drinking water and subsistence fisheries, and a decrease in stream biodiversity has already been documented in some locations coincident with water turning orange. The researchers now are looking deeper into the patterns of toxicity over time and space, such as where rusting rivers overlap with known spawning areas for migratory fish.

“The rusting river phenomenon is a good example of an unforeseen consequence of permafrost thaw in the Arctic,” Poulin said. “Further, it’s consistent with the emergence of acid rock drainage following cryosphere loss across Earth.”

NASA Earth Observatory images by Michala Garrison, using stream location data from O’Donnell, J.A., et al., and Landsat data from the U.S. Geological Survey. Story by Lindsey Doermann.

Downloads

A map of Alaska shows rusting river locations, with red colors indicating higher density. Most have been observed in the Brooks Range, stretching east-west across northern Alaska.

2007-2024

JPEG (2.16 MB)

A gently curving river runs from right to left through green tundra vegetation.

July 12, 2017

JPEG (10.91 MB)

A gently curving river runs from right to left through green tundra vegetation. A segment of the river appears orange.

July 20, 2020

JPEG (11.44 MB)

References & Resources

You may also be interested in:

Stay up-to-date with the latest content from NASA as we explore the universe and discover more about our home planet.

Examining Algal Blooms in Blue Mesa

5 min read

Using satellite data, researchers connected harmful algal blooms with warm water and low water levels at one of Colorado’s largest…

Article

Ice Moves Out of Aniak

3 min read

Spring melt along Alaska’s Kuskokwim River caused ice jams and flooding.

Article

Signs of Thaw in the Bering Sea

3 min read

Drifting sea ice fragments near Alaska’s Saint Lawrence and Nunivak islands and colorful water around the Yukon Delta heralded the…

Article

Examining Algal Blooms in Blue Mesa

6 July 2026 at 00:01




November 15, 2017
November 17, 2021

The first of a pair of satellite images shows the reservoir in November 2017, when water levels were relatively high and its color was mostly blue.
Cyanobacteria blooms turned Blue Mesa Reservoir green from September through November 2021, when water levels were among the lowest on record. The OLI (Operational Land Imager) on Landsat 8 captured this image (right) of a bloom on November 17, 2021, when the water was near its lowest level; the left image shows the same area on November 15, 2017, when water levels were closer to normal.
NASA Earth Observatory / Lauren Dauphin

The second image in the pair shows the same part of the reservoir in November 2021, when water levels were much lower and its color was much greener.
Cyanobacteria blooms turned Blue Mesa Reservoir green from September through November 2021, when water levels were among the lowest on record. The OLI (Operational Land Imager) on Landsat 8 captured this image (right) of a bloom on November 17, 2021, when the water was near its lowest level; the left image shows the same area on November 15, 2017, when water levels were closer to normal.
NASA Earth Observatory / Lauren Dauphin

The first of a pair of satellite images shows the reservoir in November 2017, when water levels were relatively high and its color was mostly blue.
Cyanobacteria blooms turned Blue Mesa Reservoir green from September through November 2021, when water levels were among the lowest on record. The OLI (Operational Land Imager) on Landsat 8 captured this image (right) of a bloom on November 17, 2021, when the water was near its lowest level; the left image shows the same area on November 15, 2017, when water levels were closer to normal.
NASA Earth Observatory / Lauren Dauphin
The second image in the pair shows the same part of the reservoir in November 2021, when water levels were much lower and its color was much greener.
Cyanobacteria blooms turned Blue Mesa Reservoir green from September through November 2021, when water levels were among the lowest on record. The OLI (Operational Land Imager) on Landsat 8 captured this image (right) of a bloom on November 17, 2021, when the water was near its lowest level; the left image shows the same area on November 15, 2017, when water levels were closer to normal.
NASA Earth Observatory / Lauren Dauphin

November 15, 2017

November 17, 2021


Cyanobacteria blooms turned Blue Mesa Reservoir green from September through November 2021, when water levels were among the lowest on record. The OLI (Operational Land Imager) on Landsat 8 captured this image (right) of a bloom on November 17, 2021, when the water was near its lowest level; the left image shows the same area on November 15, 2017, when water levels were closer to normal.

The summers of 2021 and 2022 were tough seasons for Colorado’s Blue Mesa Reservoir. A severe drought gripped much of the western U.S., prompting emergency water releases that brought the reservoir to its lowest level since 1984. Marinas and boat ramps closed, remnants of a ghost town emerged from the muck, and parts of the reservoir turned greenish and swirled with toxic cyanobacteria blooms.

Research conducted by scientists at the U.S. Geological Survey and the National Park Service analyzed decades of Blue Mesa Reservoir data and found a connection between low water levels, warm water temperatures, and harmful blooms.

“Algal blooms were more common when water levels were below 7,470 feet and water temperatures were above approximately 19.5 degrees Celsius (67.1 degrees Fahrenheit),” said Tyler King, a research hydrologist with U.S. Geological Survey. Water levels that low are relatively common and have occurred every few years in recent decades.  

While some cyanobacteria, also called blue-green algae, are always present in the reservoir in small numbers, problems occur when certain types proliferate. Aphanizomenon, Dolichospermum, and Woronichinia, for instance, thrive when the reservoir’s waters become warm and stagnant, releasing a toxin called microcystin that can cause skin and eye irritation, respiratory problems, and liver damage. Children and pets are particularly vulnerable to microcystin poisoning because of their size and tendency to ingest more water than adults.

King and colleagues analyzed in situ water samples and satellite observations from the European Space Agency’s Sentinel-2 mission and the NASA/U.S. Geological Survey Landsat satellites. A Sentinel-2 sensor that detects the light-harvesting pigment chlorophyll was particularly useful for mapping the blooms, while Landsat sensors were used to map water temperatures over time.

The National Park Service and U.S. Geological Survey launched the project in 2021 after anecdotal reports and water sampling suggested elevated cyanobacteria concentrations, King said. The scientists collected water samples but also turned to historical records and satellite data—”like a time machine,” he said—to examine conditions before regular water sampling had begun. Their analysis included satellite records of chlorophyll levels that extended back to 2016 and temperature records that reached back to 2000. The research team also studied in situ data on water levels dating to the 1970s.

A photograph taken from a rocky shoreline along the Iola Basin show mats of green growth coating the surface of the water.
A cyanobacteria bloom turned the water surface of Iola Basin green on September 8, 2021. Photo by Nicole Gibney/National Park Service.

The satellite data showed that blooms typically start in the eastern end of the reservoir, an area known as Iola Basin. The basin, where the Gunnison River flows into the reservoir, is the shallowest part of the reservoir. Occasionally, the satellite data showed, blooms spread westward into other parts of the reservoir, sometimes moving about two-thirds of the way across. However, concentrations of toxins rarely reached levels that posed health concerns beyond Iola Basin.

The same dynamics that caused challenges for Blue Mesa in 2021 and 2022 are present in 2026, said King. Drought again plagues much of the western U.S., the mountains hold little snow, and water levels in Blue Mesa are low. On June 27, 2026, the reservoir stored about 43 percent of the water it typically does on that date, the lowest value observed for that day in the past 30 years. Water levels are expected to continue dropping until October, according to U.S. Bureau of Reclamation projections

If cyanobacteria blooms emerge in 2026, the researchers expect that satellites will help scientists track them. The researchers use the U.S. Geological Survey’s WaterMAP (Water Monitoring Above the Planet) tool to monitor for potential bloom conditions within hours of satellite overpasses. NASA’s STREAM (Satellite-based Tool for Rapid Evaluation of Aquatic Environments) project also uses data from Landsat and Sentinel-2 to map potential blooms within hours of a satellite overpass, and the multi-agency CyAN (Cyanobacteria Assessment Network) project collects daily data from other satellites to map blooms in larger water bodies.

“It’s amazing that we can use satellites to map the impacts of microscopic organisms from almost 500 miles away,” King said. Yet it will still be crucial to get people out on the water taking samples and directly testing for toxins, he emphasized. “The satellites aren’t definitive,” he added. “They can tell us where there might be a problem, but toxins often aren’t present until the later stages of a bloom.”

A photograph shows two female researchers collecting green, algae-rich water in a cylindrical container.
Satellite observations can help managers decide where to send personnel to collect water samples for more detailed analysis of bloom toxicity. Photo by Katie Walton-Day/USGS.

NASA Earth Observatory images by Michala Garrison, using Landsat data from the U.S. Geological Survey. Photos by Katie Walton-Day (USGS) and Nicole Gibney (NPS). Story by Adam Voiland.

Downloads

The first of a pair of satellite images shows the reservoir in November 2017, when water levels were relatively high and its color was mostly blue.

November 15, 2017

JPEG (8.98 MB)

The second image in the pair shows the same part of the reservoir in November 2021, when water levels were much lower and its color was much greener.

November 17, 2021

JPEG (8.46 MB)

References & Resources

You may also be interested in:

Stay up-to-date with the latest content from NASA as we explore the universe and discover more about our home planet.

Low Water at San Carlos Reservoir

4 min read

Drought and water releases drained the Arizona reservoir to levels that have led to widespread fish deaths.

Article

Rising Waters Swamp Lake Naivasha

6 min read

Relentless rains are threatening a lake in Kenya’s Great Rift Valley that has become a key hub in the global…

Article

Snow Is Scarce in the Upper Colorado Basin

5 min read

The mountains of Utah and Colorado are among the areas of the western U.S. that are low on snow and…

Article

From cause to cash: a cross-border look at hacktivist activity

By: Kaspersky
8 June 2026 at 04:00

While tracking the activities of 4BID we uncovered a new string of campaigns that appear to be the work of several interconnected actors. While politically motivated groups generally limit their scope to specific nations – for 4BID and its peers, primarily Russian and occasionally Belarusian organizations – our latest findings reveal a shift. The actual geographic footprint of these attacks became broader than expected, striking companies across Kazakhstan, the UAE, Syria, and Egypt.

What triggered our investigation was spotting a cluster of indicators of compromise within a breached Russian organization’s infrastructure. We used these footprints to successfully track down other environments hit by the same threat actors and piece together the bigger picture.

This article dives into the software deployed throughout these hacktivist campaigns:

  • New ransomware samples
  • Scripts used at various stages of the attacks
  • Commercially available IT remote monitoring and management (RMM) tools

These include both updated versions of known threat-actor tools and previously unseen software.

Overlapping activity streams

Within the initial organization’s infrastructure, we found numerous activity indicators linked to several interconnected hacktivist groups – which ultimately set the direction for our follow-up analysis. We can attribute the following findings to hacktivist activity with a medium level of confidence:

  • Several samples of BlackReaperRAT, which we attribute to the 4BID group, were found alongside scripts designed to download Panorama9 RMM, AnyDesk, and Dev Tunnels.
  • Besides the artifacts listed above, we discovered ClearWater ransomware in other compromised infrastructures. Interestingly, during this same window, public sources showed Hakerskii Kit claiming a successful attack on a Russian factory. Also detected in that facility’s infrastructure was ClearWater ransomware, with the attackers publicly thanking the С.A.S. group for their contribution.
  • We uncovered several samples of Warp RAT within the hit infrastructures, which we link to the Goffee threat group. A detailed report on this specific activity will be published at a later date.

Technical details

Vulnerable web servers and fd.aspx

Analysis of the compromised environments revealed that the attackers gained initial access in most cases by exploiting the ProxyShell vulnerability in Microsoft Exchange, which allows for full server compromise.

Once inside, the attackers deployed the fd.aspx web shell – a modular ASP.NET file designed for remote control, file transfers, and system reconnaissance. Communication with the web shell relied on a basic security check: if the key parameter in an incoming request failed to match the AUTH_KEY constant, fd.aspx simply returned “Access Denied”.

Access key verification

Access key verification

If the verification was successful, the command contained in the request’s scriptText parameter was passed directly to PowerShell, and the output returned to the operator in the body of the HTTP response. In environments where PowerShell execution was restricted, the web shell swapped it out for cmd.exe. The CreateNoWindow: true and UseShellExecute: false flags were used to keep the command execution hidden from the user.

Beyond running commands, the web shell features bidirectional Base64-encoded file transfers. This allows any binary data – like executables, archives, or certificates – to be passed right inside the body of an HTTP request. The UploadFile function writes files to any directory the web server process can access, which makes it easy to drop additional shells or swap out legitimate files. The DownloadFile function exfiltrates any accessible file from the compromised system back to the attackers’ C2 server.

The web shell also includes a system reconnaissance feature that grabs the following data points:

  • OSVersion: operating system version
  • MachineName: hostname
  • UserName: current username
  • UserDomainName: domain name
  • ProcessorCount: number of processors
  • SystemDirectory: system directory path
  • CurrentDirectory: current working directory
  • Version: .NET Framework version

Additionally, the reconnaissance feature uses the DriveInfo.GetDrives() function to enumerate running processes and map out connected drives – along with the amount of free space available on each. This file system reconnaissance is topped off with LastWriteTime metadata for each object, which helps the operator quickly spot recently modified files and get their bearings within the storage layout.

Alongside the web shells, we encountered a variety of scripts and C2 frameworks across all compromised infrastructures, which we break down below.

Scripts deployed

Once the attackers gained control over a target system, they moved on to the next phase: loading their required toolkit via custom scripts. Variations of these scripts were consistently found alongside fd.aspx on compromised hosts. Most of them interact with legitimate tools, which makes them look almost identical to routine administrative scripts at first glance. The only real giveaway is the code comments, written in Ukrainian. One such script is responsible for deploying AnyDesk on the compromised host.

The build quality of these scripts is worth discussing separately. Several of them show telltale signs of AI generation; inside some compromised systems, we found multiple iterations of the exact same script, a few of which were completely broken. AI-generated code typically fails to work out of the box and requires manual tweaking to run properly.

First, the script checks for admin privileges, as it cannot proceed without them. If that check passes, it looks for an active anydesk.exe process. If the process is missing, the script fetches and installs the application directly from the official website. Once AnyDesk is successfully installed, the script configures an unattended access password and pulls the unique AnyDesk ID. All the collected details are compiled into a report and exfiltrated to the attackers’ server at 185.221.153[.]121. Because we spotted simultaneous activity from multiple groups – 4BID, Hakerskii Kit, and C.A.S. – on the analyzed hosts, this IP address could potentially belong to any one of them.

Besides AnyDesk, the threat actors leverage other legitimate tools. One example is Microsoft Dev Tunnels, a Microsoft service that exposes a local server to the internet. It’s brought into the system by a separate script that, much like the one for AnyDesk, checks if the utility is already present before downloading it from the official site. In certain instances, the utility was fetched directly from the attackers’ server instead:


Once installed, the application runs, and the resulting connection details are saved to a file named login.txt. The contents of this file consist of standard instructions for using a provided code to authenticate on a Microsoft page through a web browser.

To sign in, use a web browser to open https://login.microsoft.com/device and enter the code [CODE].

As a final step, the script opens up the required ports and creates the tunnel, giving the attackers a back door into the compromised host.

Another script we uncovered handles the installation of Panorama9, a legitimate remote monitoring and management utility. Immediately after downloading that application, the attackers configure it via the registry to hide both its system tray icon and its installation folder. To camouflage the Panorama9 services, the attackers rename them to Windows Update Helper and Windows Update Helper Cache and swap out their descriptions, making the utility look almost identical to standard system components. Once the utility finishes its job, the script clears its tracks.

The attackers used a dedicated script to establish persistence on the system. When executed, it used the net user command to spin up a local user account and then hid it via the registry. The script added this new user to every available local group; if the machine was domain-joined, it also attempted to inject the user into all Active Directory groups.

At the same time, the script tweaked RDP settings: it set the minimum encryption level through the registry, added a firewall rule to allow port 3389, and ran the relevant services.


After it wrapped up its main tasks, the script wiped the event logs, command history, temporary files, and finally itself. Once the attackers got what they wanted out of the infected host, they triggered another script that removed the previously created user account, cleaned out the registry keys generated during the earlier phases, and then deleted itself as well.

The scripts described here are just the most telling examples out of dozens of samples we found. An analysis of the attackers’ toolkit reveals a clear trend: they aren’t just fine-tuning the solutions they’ve used in the past (specifically, the AnyDesk deployment script), but are actively broadening their arsenal with new tools like Panorama9, Dev Tunnels, and others.

Publicly available utilities

As previously mentioned, the attackers leverage a broad spectrum of dual-use public software, such as all kinds of remote monitoring and management utilities. While they use the scripts discussed above to drop some of the utilities onto systems, we didn’t encounter scripts for others, so we can’t confirm whether any exist. We observed the following tools deployed across the campaigns in question:

  • AnyDesk: a remote administration tool
  • Advanced IP Scanner: a network scanning utility
  • Dev Tunnels: a Microsoft service used for exposing a server to the internet
  • Panorama9: an IT infrastructure management and monitoring service
  • Nezha Monitoring: a server status monitoring utility
  • Tactical RMM: a remote monitoring and management tool

C2 and communications

To gain a foothold in the victim’s infrastructure, the attackers relied on several post-exploitation frameworks. Some of these are publicly available utilities, while others are custom-built.

Among the publicly available tools in the group’s arsenal are:

  • Sliver
  • Havoc
  • Apollo Mythic
  • Adaptix

We also discovered a previously undocumented backdoor, dubbed BlackSalt, which contacts the C2 server to fetch commands and executes them via cmd.exe.

Sliver

On several hosts, following the initial Microsoft Exchange server compromise, files named upd.exe, winhost.exe, update1.exe, update.exe, and akolo.exe were dropped alongside the previously mentioned fd.aspx files and scripts. All of them were located in the C:\Windows\System32\inetsrv\ directory and were configured as SFX archives with nearly identical payloads, which ran an install.bat script upon extraction.

Contents of the SFX archive

Contents of the SFX archive

The install.bat script contents

The install.bat script contents

The script copies the malicious components into the Windows folder and installs servicechecker.bat as a system service. To do this, it leverages the legitimate Windows Service Wrapper (WinSW) utility included in the archive under the filename backupsrv.exe. The archive also contains the WinSW configuration file, backupsrv.xml, which specifies exactly which script should be registered as a service. Once installed, servicechecker.bat is configured to run automatically on system boot.

The servicechecker.bat script, in turn, runs backupagnt.exe, a loader for the main malicious component housed in WindowsInternal.UpdateComponent.dll. This file was built with the help of the Donut utility and is encrypted with a simple single-byte XOR key (0x0F). Its primary job is to inject the Sliver code straight into the device’s memory.

The backupagnt.exe loader code

The backupagnt.exe loader code

All Sliver instances uncovered during this investigation were configured to communicate with the C2 server at 185.221.153[.]121 over mTLS.

Havoc

Inside a similar SFX archive located in the user directory $user\desktop\ under the filename demon.x64.exe, we found another post-exploitation framework: Havoc. This instance was configured to communicate with the C2 server at 77.72.85[.]62.

Apollo

Mythic Apollo is a cross-platform post-exploitation agent used within the Mythic framework to manage compromised systems. It provides a persistent connection to the C2 server, executes operator commands, handles file uploads/downloads, runs arbitrary code, and supports expansion via plugins. We previously provided a detailed breakdown of the Mythic framework in our post, Hunting for Mythic in Network Traffic.

Here is an example of the Mythic Apollo configuration we encountered in these hacktivist attacks:


This specific sample of the .NET Mythic Apollo agent was compiled with an extensive suite of modules and supports multiple transport profiles that enable communication via HTTP, TCP, WebSocket, SMB, named pipes, and web shells. The C2 address 77.72.85[.]62 is hardcoded into its configuration.

Adaptix

AdaptixC2 is another post-exploitation framework in the attackers’ arsenal. This is a relatively new open-source project, which we broke down in our post, Adapt or pay:an analysis of the AdaptixC2 framework.

The agent samples discovered during our investigation into these hacktivist campaigns consist of a packed AdaptixC2 Beacon delivered via a custom x64 loader. Upon execution, the payload decrypts an embedded shellcode, allocates memory, and executes the malicious payload using the CreateThread WinAPI function. Packed inside the shellcode is the AdaptixC2 Beacon agent in DLL format, featuring a configuration encrypted using RC4.

According to the AdaptixC2 classification system, this agent falls under the BEACON_HTTP type. It is capable of executing commands, performing file operations, enumerating and killing processes, launching new programs, and exfiltrating data back to the C2. It also supports SOCKS port forwarding and BOF modules.

AdaptixC2 uses encryption to keep its configuration under wraps. The corresponding block contains the data size, the actual RC4-encrypted configuration, and a 16-byte key.

Example agent configuration

Example agent configuration

Example of agent requests pinging the C2 address, as flagged by Kaspersky solutions and displayed in Kaspersky Threat Lookup

Example of agent requests pinging the C2 address, as flagged by Kaspersky solutions and displayed in Kaspersky Threat Lookup

BlackSalt Backdoor

During the investigation, we also came across target infrastructures running vulnerable versions of Microsoft Exchange where – much like the Sliver cases – SFX archives named WindowsServiceHelper.exe were discovered in the C:\Windows\System32\inetsrv\ directory. Once extracted, the archive executed an install.bat file.

SFX archive contents (09d0517a1f69feff8186655ae3b567e0)

SFX archive contents (09d0517a1f69feff8186655ae3b567e0)

The install.bat script contents

The install.bat script contents

Similar to the other archives of this type, the script uses the WinSW utility to install the malicious components. In this specific case, however, the primary payload is a file named svc.exe, which turns out to be an obfuscated backdoor written in VBS. Much like the deployment scripts used for the remote management utilities, the code of this setup BAT script was clearly put together with AI tools and features comments in Ukrainian.

Main backdoor loop

Main backdoor loop

The backdoor is essentially a textbook reverse shell. Its capabilities boil down to fetching commands from the C2 server at 45.150.109[.]2, executing them via cmd.exe, and piping the output back to the C2.

EDR killers

In their attacks, the threat actors deploy what are known as EDR killers: malicious tools designed to disable security software on the system. In the vast majority of cases, these utilities rely on the BYOVD technique.

On the hosts compromised during these hacktivist operations, we discovered samples named kil.exe and Killer.exe. These are modified versions of the public, Rust-based BYOVD project EDRKiller. The attackers streamlined the utility to act strictly as a client for the driver and expanded the hardcoded list of security processes to terminate. The sample targets the vulnerable Warsaw_PM driver, though it lacks the functionality to load the driver itself – the attackers drop it onto the system separately.

The general workflow plays out as follows:

  1. In user mode, the program finds the PID of the target process.
  2. It opens a handle to \\.\Warsaw_PM.
  3. It constructs a buffer containing the target process’s PID.
  4. It calls DeviceIoControl.
  5. The driver executes the calls:
    • ZwOpenProcess;
    • ZwTerminateProcess.

The EDR killer continuously enumerates processes, repeatedly sending the IOCTL and terminating the target processes every single time they pop up.

Example of the process list storage inside the EDR killer

Example of the process list storage inside the EDR killer

Both kil.exe and Killer.exe share the exact same list of processes targeted for termination:

MsMpEng.exe, SenseIR.exe, SenseNdr.exe, SenseCncProxy.exe, SenseSampleUploader.exe, NisSrv.exe, avp.exe, kavfs.exe, bdagent.exe, bdservicehost.exe, vsserv.exe, AvastSvc.exe, AvastUI.exe, aswidsagent.exe, avgsvc.exe, mfemms.exe, mfefire.exe, mfevtps.exe, dwengine.exe, dwservice.exe, elastic-agent.exe, elastic-endpoint.exe, Sysmon.exe, wazuh-agent.exe, ipban.exe

Another utility used to kill security software processes is ghostdriver.exe, an unmodified build of the open-source project GhostDriver. In this case, the attackers simply pulled a version straight from GitHub and didn’t modify any of its code.

Example of output from the GhostDriver utility

Example of output from the GhostDriver utility

The tool operates through the following stages:

  1. Identify target processes
    The program takes a list of process names (such as msmpeng.exe) via command-line arguments. If no list is specified, it falls back to a default set.
  2. Enumerate system processes
    To locate PIDs, the tool relies on standard Windows APIs:
    • CreateToolhelp32Snapshot
    • Process32First
    • Process32Next
  3. Generate a list of processes to kill.
  4. Load the vulnerable driver
    This is the core phase of the utility’s operation. During this step:
    • The sys driver is written to disk.
    • A SERVICE_KERNEL_DRIVER type service is created.
    • The driver is kicked off via the Service Control Manager (SCM).

GhostDriver.sys is hardcoded inside the GhostDriver executable and is a binary driver known as RentDrv2 (BadRentdrv2).

It contains the CVE-2023-44976 vulnerability, which allows it to:

  • Accept user-mode commands via DeviceIoControl.
  • Perform operations on processes from kernel mode.
  • Bypass security mechanisms, including Protected Process.

Upon execution, GhostDriver drops RentDrv2 to disk, loads it into the Windows kernel, and connects to it via the virtual device \\.\rentdrv2. The utility then issues command 0x22E010 to the driver, passing along the target process ID, and the driver terminates that process directly from kernel mode.

GhostDriver runs in a continuous loop. Every ~700 ms, it rescans for the target processes and sends out termination commands.

After the driver starts up, the utility attempts to delete the ghostdriver.sys file. To do this, it opens a file handle, uses the SetFileInformationByHandle WinAPI function to rename it to something like :GhostDriver, reopens the handle, and marks the file for deletion via FileDispositionInfo. Before wrapping up, it also tries to stop and remove the driver service, and delete the C:\rentdrv.log file where the driver writes its logs.

Example of the adversary command execution launching GhostDriver:

Current versions of Kaspersky products are resilient to these types of attacks: the utilities described in this post cannot terminate their processes.

Connection to the ClearWater ransomware

Alongside the previously described Mythic Apollo samples (C2: 77.72.85.62), backupagnt.exe loaders, and Panorama9 deployment scripts, we discovered a new ransomware strain named ClearWater across several compromised infrastructures. Written in C++ and compiled with GCC (MinGW), the sample is a 64-bit Windows executable. It features zero obfuscation; in fact, the binary wasn’t stripped of its DWARF debug information. This makes analyzing the sample significantly easier and points to either sloppiness or a lack of technical expertise on the developers’ part.

Original function names preserved within the Trojan's body

Original function names preserved within the Trojan’s body

When executed, ClearWater logs its progress in a separate console window.

The console window displayed upon launching the Trojan

The console window displayed upon launching the Trojan

File encryption

Like most ransomware strains, ClearWater is a Trojan designed to locate and encrypt the victim’s files. The Trojan executable contains a hardcoded RSA-2048 primary public key in PEM format.

For every file it processes, the ransomware generates a new 32-byte key and a 12-byte nonce – though only 8 of those 12 bytes are actually used – and encrypts the file’s contents via the ChaCha20 symmetric algorithm. The ChaCha key is then RSA-encrypted and appended to a specific data structure at the end of the file. To pull this off, the malware leverages cryptographic implementations from the open-source libsodium library.

struct
{
	uint8_t label[4];			//'M', 'Y', 'E', 'K' marker
	uint32_t rsa_encr_size;		//size of RSA-encrypted data
	uint8_t rsa_encr_data[256];	//RSA-encrypted ChaCha key
};

The Trojan processes all files except those with a .txt extension. This approach can easily break installed software, as it blindly encrypts both libraries and executables; however, it does explicitly skip the system directory during its search. Encrypted files are additionally appended with the .clear extension. The malware scans for targets on local drives as well as SMB network shares, which it maps out by using the net view command.

Additional functionality

Within every directory it processes, the Trojan drops the attackers’ demands into a file named CLEARWATER_README.txt.

Ransom note:

Ransom note:

Additionally, by modifying the HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run registry key, the malware sets up a persistence mechanism that automatically opens the ransom note with notepad.exe on startup.

ClearWater is distributed inside a self-extracting archive. The extraction script runs in silent mode (GUIMode=”2″), escalates privileges via a UAC prompt, drops the Trojan at C:\ProgramData\ClearWater_x64.exe, and kicks it off. Once the ransomware finishes running, the SFX archive cleans up after itself and wipes the original archive (SelfDelete=”1″).

Alongside this script and the Trojan executable, the archive includes a BMP image. The ransomware sets this image as both the desktop wallpaper (by tweaking the HKEY_USERS\<…>\Control Panel\Desktop\Wallpaper registry key and calling SystemParametersInfoA with the SPI_SETDESKWALLPAPER parameter) and the lock screen background (by modifying the LockScreenImagePath and LockScreenImageUrl values under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\PersonalizationCSP).

Two variants of the desktop and lock screen image

Two variants of the desktop and lock screen image

To complicate system recovery after the attack, ClearWater performs several actions typical of ransomware:

  • Deletes shadow copies using the following commands:
  • Wipes the backup catalog and disables Windows Restore:
  • Removes restore points:
  • Disables the system startup recovery option:

ClearWater also features a kill_all_non_whitelisted_processes() function designed to terminate active tasks, though it doesn’t actually call it during execution. This function leverages PowerShell to look up and kill any process whose name isn’t included in a hardcoded allowlist within the Trojan’s body. It uses the following PowerShell code to do this:

Get-Process|Where-Object{$w -notcontains $_.Name.ToLower()}|Stop-Process -Force

The exclusion list contains various essential system processes and breaks down as follows:

system, idle, smss, csrss, wininit, services, lsass, winlogon, svchost, explorer, dwm, shellexperiencehost, runtimebroker, trustedinstaller, tiworker, textinputhost, taskhostw, mousocoreworker, fontdrvhost, audiodg, sihost, spoolsv, taskeng, taskhost, searchui, securityhealthservice, startmenuexperiencehost, searchindexer, backgroundtaskhost, sppsvc, wmiprvse, wudfhost, vboxservice, vboxtray, vmtoolsd, vmwaretray, vboxguest, vmsrvc, vgauthservice, vmacthlp, qemud, qemu-ga, msdtc, searchprotocolhost, wlanext, dllhost, conhost, comppkgsrv, msmpeng, mssecflt, systemsettings, securityhealthsystray, nvtray, nvvsvc, ravbg64, igfxtray, igfxem, igfxcuiservice, igfxhk, igfxext

Updated Blackout Locker

In a previously published report (link in Russian) on collaborations between several hacktivist groups, we highlighted a tool called Blackout Locker. In late January 2026, the 4BID group ran a series of attacks against organizations in Russia using an updated version of this malware. This section breaks down the new version of Blackout Locker and covers its key characteristics uncovered during our analysis.

Rust dropper

The attackers use a dropper written in Rust to distribute Blackout Locker. Depending on the specific sample, the dropper first carries out a series of staging actions. It then writes the payload executable to …\Users\[USERNAME]\AppData\Local\Microsoft\[REDACTED].dat and swaps its extension to EXE by calling the Windows command prompt:


After that, it launches the renamed executable.

Blackout Locker

The primary tool deployed in the attacks in question is an updated version of Blackout Locker.

Our analysis revealed that the key difference in this new version is the addition of a screen locker component, which it drops and executes in tandem with the ransomware’s main background payload.

During the initial phase, the screen locker file is created under the following paths:


To launch the screen locker, several tasks are created:


The screen locker is also written to the following registry keys:


After this, two LNK files, SystemHelper.lnk and WindowsHelper.lnk, are created via PowerShell for subsequent execution:

  • The first file is placed in the %PROFILEPATH%\All users\Start menu\Programs\Startup directory:
  • The second file is placed in the %USERPROFILE%\Start menu\Programs\Startup directory:

As a result, a shortcut is created in the startup folder pointing to WindowsSystemHelper.exe located on the desktop. This ensures the screen locker appears every time the user logs in. Even if the victim enters the correct password into the locker window, it will keep popping back up; while the window itself closes after password entry, the corresponding task is never actually deleted.

Screen locker

During execution, Blackout Locker generates a file named README.txt, which the screen locker later references to pull the text displayed to the user. Some Blackout Locker samples drop a ransom note written in English:

On the lock screen, it may look like this:

Other samples deploy a ransom note in Russian:

If the program fails to read README.txt, it falls back to a hardcoded ransom message. If this fallback message is in Russian but the victim’s operating system lacks support for Cyrillic encodings, the loader’s on-screen output renders as garbled text.

Attack geography

The majority of the compromised infrastructures belong to Russian and Belarusian organizations, which aligns with the stated agenda of these hacker groups. However, for the first time, we identified victims in other countries with no relation to this agenda: Kazakhstan, the UAE, Syria, and Egypt. Within the network of a Kazakh aviation company, we detected multiple post-exploitation frameworks pointing to C2 servers at 77.72.85[.]62 and 185.221.153[.]121, traces of the Panorama9 and Tactical RMM platforms, and backupagnt.exe loaders. A similar footprint was observed in the infrastructure of an Egyptian hospital, though the familiar toolkit was augmented by the fd.aspx web shell. The remaining international victims exhibited a nearly identical combination of artifacts, with only minor variations.

While the primary targeting vector previously centered on Russia and Belarus, the threat actors now appear to be pivoting their attention toward the wider CIS region and the Middle East. This strategic shift correlates with a statement from a member of the 4BID group, who claimed that attacking Russia is no longer profitable.

Takeaways

The hacktivist groups discussed in this report are steadily expanding the geographical footprint of their campaigns, pushing beyond Russia and the wider CIS region. Alongside this expansion, we observe the growing use of ransomware and other tooling consistent with financially motivated operations, which may further influence their choice of victims.

This shift underscores the critical need for continuous threat landscape monitoring. To stay ahead of threat actors, organizations must look beyond the immediate risks facing their perimeter and proactively track emerging threats, including the tactics of groups targeting specific industry verticals or geographic regions.

Detection by Kaspersky solutions

Kaspersky solutions reliably detect the malicious activity in question at every stage of the malware lifecycle. This section outlines potential detection scenarios.
Publicly available dual-use software leaves numerous artifacts on targeted hosts, which helps Kaspersky Endpoint Detection and Response Expert trace the activity of these utilities.

For instance, network connections established with Panorama9 servers both during the initial software launch and throughout the tool’s operation trigger the panorama9_dns_activity rule. The Hunt Hub section of our TI Portal features detection rules for other event types and specific operating systems, searchable with the keyword panorama9. Similar rules exist for the other utilities described in this post: Tactical RMM, Nezha, and Dev tunnels.

GhostDriver.exe relies on an embedded vulnerable driver, which it drops onto the target host. The creation of these drivers is detected by the vuln_driver_created_by_unsigned_process rule family.

Ransomware is inherently quite noisy and so can be detected at various execution phases. The execution graph within Kaspersky Cloud Sandbox on our Threat Intelligence Portal visualizes the entire ClearWater execution chain, capturing key behaviors such as modifying the desktop wallpaper and deleting shadow copies.

ClearWater execution graph in Kaspersky Cloud Sandbox

ClearWater execution graph in Kaspersky Cloud Sandbox

Additionally, the Threat Lookup and Research Graph sections of Kaspersky Threat Intelligence Portal allow you to visualize and analyze the connections between the malicious domains and files used by the adversaries.

Visualization via Research Graph on Kaspersky Threat Intelligence Portal

Visualization via Research Graph on Kaspersky Threat Intelligence Portal

Kaspersky Threat Lookup demonstrating the connection between malicious files and the attackers' IP address

Kaspersky Threat Lookup demonstrating the connection between malicious files and the attackers’ IP address

Monitoring network traffic is another highly effective method for detecting the malicious activity described here. Kaspersky Anti Targeted Attack (KATA) with the NDR module detects the network communications of all malware samples in question utilized throughout this campaign.

For instance, upon detecting HTTP network activity characteristic of the BlackSalt backdoor, the system triggers an alert for the Backdoor.BlackSalt.HTTP.C&C rule triggering.

Examples of using the Kaspersky Anti Targeted Attack (KATA) platform with the NDR module to detect other agents described here – along with their detailed technical analysis – are available in our dedicated reports on Adaptix and Mythic detection.

Indicators of compromise

Web shells
26100db3f56880110a92a2b4742d6eaf fd.aspx
cf682a6fee80a78be578b1edd82627fa fd.aspx
2d5533fb65ebb50a5a5fd53e62d73b9a fd.aspx
fe04d230db612ea24af3826fda667131 fd.aspx
Scripts
2db94ee3ec69988588702bd77999a5d4 any_local.ps1
f88d2b5c3b885ad5a9c1c44551bccc60 main.ps1
1e1edf879b2dc6c9892a22bfa5985db1 main.ps1
78250fa890220821e2b91e31b965de59 main.ps1
f2af797ac45b9f578c53cc49e5797397 auto_dev.ps1
0c32bfdf83ecebe3a1399d261dc8ff57 auto_dev_test.ps1
e14cc9a959bbe16c48b8dff063b311f3 auto_dev_test_multimple_task.ps1
36b3be503c6e34613ff50cb28e0f3ddb auto_dev_test_multimple_task.ps1
c12ebe625737ed0908b045e811f14ecd tun.ps1, auto_dev_test_multimple_task.ps1
1c0924f5711a24821921de5ad822213b grant.ps1
d78adab5e16c26d4cd14fe38f77e29e6 pan.ps1, pam.ps1
6cf548445c39aff844be96d73c89e376 test.ps1
911a21aa999c324dc960d3498eec528e radiant.ps1
68e310de44c3165ffffa25bc495d6fc5
4f41a22b3e7469fb6b45a42d71ec7087
80e5bde401d6b0ca96015ae9cfeb6535
1c82a94c362a9e98a66ae57d6ff37900
fa04aeedc0d2f5bb6ed357fdae1c1435
AdaptixC2
555a6722436d7cf7de396e0c57d32a27
b974141ff9ad1efb60dd9e16977266ca
7da855b2fd9b52f9088e64d656164637
d08056c2ac28933d6843658c2c8c574f
038cab0c60c53cf12f048272014024c0
c183033d86d2e052b8eb0deb2136ab29
bc0ebf67986eea803b4c9633ed3a4bb5
18618f4b468ba4e64c2e1072a6da2134
1742a9fa35e253614b76ac0f687ba02e
c7eb6da3aa216816079a1b785097552a
3ee38b944e5c83922f99641846f7db0c
d8ff7f417d56fa2a3baf3c8933013a25
1ff222457f5e0e32adfa8341f260dde7
ede8ce887dd9ab7add0f0fc872d51369
1344e6bc51cea35befb4adff7a25899b
2a09162d72aa416e18bab46070043a13
841b7d3863b49f62d4faa9949ff5df38
1bd1ca848b15530e39792b4fe6f31367
Mythic Apollo
b36968b98046d1b033d84f292e7ca1cb
663a479d6d24c767f1d3229a0a91554b
54a308f734095d54ae0e1c86c849a2d8
3137958eb830186826d486afd9222aee
1d09499cb2d7d70df903b60602a58887
d74262f968dc3f378c4021a89d16a292
3d9cbc944f9a9e127550ffb4e8394965
bcd3859f4ddd72c4690d76c3b4ef8955
3a9b0875fc692944c180b165a83a0d17
c558e6a9d0a697c757aa6d7782e269c9
61647db645f7cc221046999ef1dbe1d1
02493e1cb684be6a1a1fc6334a56c516
a3dba01c76571adc0797801ff30f2b90
3f4fbba101b209b00e70787fd5bab819
cd0c5b9e4e47df4231d02ed87ff49f26
b8a13e808b5b5f1836d3e559755139d0
60f8b115aec8a13b0069efc84fc645f5
da55b5612a80ef20ec75b68151e7ff4b
7d35b4961914ad83a57f8832d8e870d8
334abbdc99d359aab2ea371dd4eda5f2
389a1bbdbf5c91bd1c179227f5ae0923
87d48fbccb4aaee95222e215ecb7ebec
76c819185e3c8b8557a2c3986ab80a7c
6d19c8eea11d50c01d20f18382a964d1
Other C2 frameworks
8db0adf8fd6dc6195d7ae55e37e49f97
08f3a14a2337eb9936c38f5159be007c
717ab7624c192f6f8dd38994116c28dc
d1c51b92939aa168f0951a8368841373
5398b7eaa94f0ee570b1c5642b559047
d65a79ea9257637c77cab6e087468912
008cd423ca45134d3343f66cced1d104
9741672506f26813c71839aaa6aa3882
06bed0a0906e52c764b3b7016d6a4428
upd.exe (SFX archive)
08c069f133ac27cbc02a0ed79e4e87ba upd.exe
a36082c998391a3ebaf05ba4f834172c backupagnt.exe
9810ea6752112b3569ddc096e1a72e1d sliver
update1.exe (SFX archive)
10824d14c814524155f2b529cf5fee43 update1.exe
a36082c998391a3ebaf05ba4f834172c backupagnt.exe
9810ea6752112b3569ddc096e1a72e1d sliver
akolo.exe (SFX archive)
242038139842ec79ec1044c64eb0804a akolo.exe
53ba13cc6066adfd67f8098c0a5b8dde backupagnt.exe
9810ea6752112b3569ddc096e1a72e1d sliver
update.exe (SFX archive)
84bb66a982710c5536143a07d84e8749 update.exe
a36082c998391a3ebaf05ba4f834172c backupagnt.exe
9810ea6752112b3569ddc096e1a72e1d sliver
akolo.exe (SFX archive)
fa3c222f6b53d6a2e35a54600f6aa011 akolo.exe
0b1870d57221eec6f3bbef648e71a724 backupagnt.exe
5e81f72614db42615489266be11b1d09 sliver
akolo.exe (SFX archive)
4c8a0531653b5398a35c6b1b80ff1350 akolo.exe
83f66862c0cc40da20236fd6b47138fd backupagnt.exe
5e81f72614db42615489266be11b1d09 sliver
[REDACTED].exe (SFX archive)
56be07e46fd452315008ed246ebbf52b [REDACTED].exe
579e8bbd6a5bcca89b5acd6fb5db32db backupagnt.exe
dd8fea244afc8223b961f1d9d6ac8c5d Apollo
WindowsServiceHelper.exe (SFX archive)
09d0517a1f69feff8186655ae3b567e0 WindowsServiceHelper.exe
62123c39477389d500e74e82782adea5 BlackSalt Backdoor
winexe.exe (SFX archive)
6d365de5c5a13006b7cadd6bc6876e84 winexe.exe
2f40bcee90abed0898e92521da17e52d BlackSalt Backdoor
WindowsServiceHelper.exe (SFX archive)
6dfef58ef68fb7965a23da8be3141af9 WindowsServiceHelper.exe
56d1de3159adbfda20aca593c99901f9 BlackSalt Backdoor
[REDACTED].exe (SFX archive)
96dbdc2651d829bf9ba35674dd4bfcae [REDACTED].exe
129225b3e93c17f131bcc2a982ffb09a BlackSalt Backdoor
test.exe (SFX archive)
9f37fff7e5d22f83fc1c0872ad5332f9 test.exe
cf54f6cbdb4dbf1ce6fc2e5be4ca3b20 BlackSalt Backdoor
1.exe (SFX archive)
e99efd77392e2b4fe4d9bf5728a12b98 1.exe
129225b3e93c17f131bcc2a982ffb09a BlackSalt Backdoor
WindowsServiceHelper.exe (SFX archive)
f2dc794bf93887e281ad89209493065a WindowsServiceHelper.exe
2f40bcee90abed0898e92521da17e52d BlackSalt Backdoor
EDR killers
d13997b1716e4c82ab454285202eafdc killer.exe, 2.exe
ecb57d8793514aa02314417265b1853f kil.exe, 3.exe
3b974ff986445e5944c51179d19bd6be GhostDriver.exe

Network indicators
212.46.12[.]182
185.221.153[.]121
77.72.85[.]62
45.150.109[.]2
130.49.155[.]112
45.112.194[.]82
138.226.236[.]52
85.137.253[.]186

‘Forever chemicals’ are everywhere — but these companies are out to destroy them

30 June 2026 at 09:11
Heather Koponen at her family home on the outskirts of Fairbanks, Alaska. She was stunned to learn that the well built by her parents in 1966 is contaminated with PFAS. (Photo courtesy of Koponen)

Subscribe to Positive Charge: Apple Podcasts, Spotify, Amazon Music, All Episodes

It was on something of a lark that Heather Koponen went to a screening of “Dark Waters” — the Mark Ruffalo film about dangerous “forever” chemicals fouling creeks and drinking water.

She really liked the movie and took home a free test kit offered by the nonprofit that organized the event to check her own drinking water for the pollutants, known as PFAS.

Koponen, a retired physician’s assistant, lives on the outskirts of Fairbanks, Alaska, in a home that once belonged to her parents. She knew about PFAS contamination in the area from firefighting foams used at military bases and airports, and had local friends who believed their health had been harmed by the chemicals. Koponen thought she was in the clear given her location relative to potential sources.

“Surprise, surprise, the well that my parents had put in in 1966, had the best-tasting water in the world and was west of the known contamination, turned out to have high levels of PFAS,” Koponen said. “We didn’t believe it, so we tested again, multiple times.”

PFAS — a family of industrial chemicals used in non-stick pans, food packaging, and as a grease and water repellent in clothes and carpets — contaminate water and soil across the U.S. and the world. Most people have detectable levels in their blood.

The chemicals are linked to reduced immune response, developmental delays in children, increased incidence of some cancers and hormonal impacts such as decreased fertility.

As PFAS have spread through the environment, strategies for controlling and destroying the persistent pollutants have been in short supply and extremely costly.

Now, decades into the problem, that’s finally changing. On this debut episode of Positive Charge, GeekWire’s podcast about hope in the sustainability and climate fight, we go inside the effort to build and deploy technologies that can effectively destroy PFAS. Two companies at the forefront are based in Western Washington: Aquagga and Sedron Technologies.

Blasting PFAS in Tacoma

Calvin Rhodes, mechanical design engineer for Aquagga, is suited up in safety gear for working with PFAS. (GeekWire Photo / Lisa Stiffler)

Located in downtown Tacoma, Aquagga does its R&D work inside the Petrich Marine building — a former marble works facility on the industrialized Thea Foss waterway. Inside the cavernous wooden structure, the startup builds devices that treat PFAS pollution from concentrated sources, housed in easy-to-move shipping containers painted bright white.

“We can step inside,” said Brian Pinkard, Aquagga’s co-founder and chief technology officer, letting visitors inside one of the containers. “It’s a little dirty. Watch your step. Just don’t touch anything. That’s the one rule.”

The system uses hydrothermal alkaline treatment, or HALT, blasting PFAS with high temperatures and extremely alkaline conditions — imagine a very strong bleach. Contaminated wastewater flows through the machine, and the process breaks the chemicals into smaller, nonhazardous components, including carbon and fluoride compounds.

What comes out isn’t drinking-water safe, but the technology destroys more than 99.99% of PFAS.

In recent years, Aquagga has treated contaminated water from various sources, including a lined underground pit that once held 20,000 gallons of waste at Fairbanks International Airport. A project with the Department of Defense treated 3,000 gallons of waste in North Carolina. DOD alone has an estimated 2 million gallons of PFAS-containing firefighting foam stockpiled for disposal.

Turning waste into a weapon against PFAS

Cheeky swag at a Sedron Technologies event. (Sedron Photo)

Sedron wasn’t launched to battle PFAS. It set out to purify sewage waste into drinkable water — which it once served to Microsoft co-founder Bill Gates.

Janicki Industries, an aerospace engineering and manufacturing company, received funding in 2011 from what is now the Gates Foundation. The philanthropy wanted a wastewater purification system for use in developing countries. That project led to the creation of Sedron.

The company developed systems to treat dairy waste and municipal biosolids — the residual product from wastewater treatment plants. Sedron dries the biosolids in an energy-efficient thermal dryer, turning them into a biofuel fed into a biomass boiler. The boiler generates electricity that cycles back to power the dryer and produces excess clean energy sold to the grid.

The system also destroys PFAS that contaminate sewage waste, having escaped from consumer goods or passed through humans.

“When you’ve got biosolids in these thermal systems that are heated above 900 degrees Celsius, they’re in there for over two seconds, and there’s enough turbulence within that system, the literature suggests, that PFAS is destroyed,” said Meghan Carlo, Sedron’s senior permit manager.

Without this treatment, biosolids would typically be returned to the environment as fertilizer spread on farms, golf courses or similar sites — keeping PFAS in circulation.

The long road to clean water

Groundbreaking at Sedron’s South Florida treatment plant. (Sedron Photo)

Solutions for cleaning up PFAS exist, but the scale of the problem is staggering. One academic study estimated the cost of removing a subclass of PFAS from the environment at the same rate they are released: somewhere between $20 trillion and $7,000 trillion per year.

In 2024, the Biden administration established the country’s first drinking water limits on six forms of PFAS, setting a ceiling of 4 parts per trillion — roughly a tiny drop of water in five Olympic-sized swimming pools. The Trump administration is moving to cancel limits on four of the six and delay compliance for the other two.

States are forging ahead with their own restrictions on PFAS in drinking water, including monitoring requirements and limits on how and where the chemicals can be used. The resulting liability concerns for municipalities and other stakeholders are stoking demand for cleanup technologies.

Aquagga has devices available for lease, purchase or demonstration projects. Sedron broke ground this year on a regional waste treatment facility in South Florida that will serve municipalities home to 2 million people, with operations expected to begin in 2028.

Fairbanks resident Heather Koponen needs a solution now. Her options include an hour-long round trip to a natural spring to fill five-gallon jugs, deliveries from a local company whose water appears to have low-level PFAS contamination, or PFAS filters similar to a Brita.

But she’s also focused on the bigger picture.

“The most important thing is to stop more contamination,” she said. “We’ve got to think of future generations and the future planet.”

Sources and references

Interviews:

  • Brian Pinkard, Aquagga, co-founder and chief technology officer
  • Heather Koponen, Fairbanks, Alaska, resident impacted by PFAS
  • Stephanie Dotterer, Sedron Technologies, director of strategy
  • Meghan Carlo, Sedron Technologies, senior permit manager

Additional sources:

❌
❌