CiberLATAMbywhalemate

ColCERT warns on ORB3 relay network

ColCERT, INCIBE, and ECUCERT flagged active malicious activity, including brute force in Colombia and an exploited ColdFusion flaw.

Whalemate Labs · AI-assisted researchJul 12, 20263 min read

On July 10, 2026, ColCERT said it had found at least 16 nodes tied to an ORB3, SPACEHOP, and CHARLIE network used for scanning and massive brute-force attacks against SSH, PostgreSQL, and Apache Tomcat. At the same time, INCIBE warned about a critical Adobe ColdFusion flaw already under active exploitation, while ECUCERT issued an alert on the Wallstreet ransomware.

ColCERT spots active ORB3, SPACEHOP, and CHARLIE infrastructure in Colombia

On July 10, 2026, ColCERT issued Alert 102, titled "Operative Relay Network CHARLIE Alert," reporting at least 16 confirmed nodes linked to an ORB3, SPACEHOP, and CHARLIE network. According to the notice, the infrastructure is carrying out scans and large-scale brute-force attacks against SSH on TCP/22, PostgreSQL on TCP/5432, and Apache Tomcat on TCP/8080 using the BruteEntry binary, written in Go.

The alert adds that BruteEntry is being installed on compromised edge servers belonging to telecom companies in Colombia. Once active, it registers with a C2 server identified as UAT-9244 and requests batches of up to 1,000 target IP addresses to launch brute-force attacks against exposed services.

ColCERT advised Colombian organizations to block network egress from compromised hosts, begin incident response procedures, and specifically look on Windows hosts for the wsprint.exe process loading unsigned DLLs from C:\ProgramData\ as a possible indicator of compromise tied to the ORB3 and CHARLIE relay network.

The same alert says the nodes reuse generic SSL certificates with Subject and Issuer C=US, CN=SERVER and C=US, CN=CA. It also warns about certificates with validity periods longer than 10 years, for example from 2022 to 2042, in HTTPS connections to IP ranges not recognized as a possible sign of malicious infrastructure.

ColdFusion flaw under active exploitation

On July 7, 2026, INCIBE-CERT published critical alert INCIBE-2026-473 on CVE-2026-48282, a path traversal vulnerability in Adobe ColdFusion that allows remote code execution without user interaction on affected ColdFusion 2025 and 2023 servers. According to the alert, the issue stems from incorrect path restriction to a restricted directory, which allows manipulated requests to read arbitrary files and, eventually, execute remote code in the context of the server's current user.

INCIBE-CERT also said the vulnerability is being actively exploited and that exploitation does not require victim interaction. The agency said this can lead to privilege escalation and bypass of security mechanisms on affected platforms.

Affected versions include ColdFusion 2025 up to Update 9, and ColdFusion 2023 up to Update 20. Adobe released fixes in ColdFusion 2025 Update 10 and ColdFusion 2023 Update 21 as the full remediation. INCIBE-CERT recommended applying those updates urgently, reviewing logs for possible prior compromise, and, if patching is not immediately possible, implementing network segmentation, restricting access to the admin panel, and closely monitoring inbound connections.

Adobe also confirmed that CVE-2026-48282 was being exploited in limited attacks against Adobe ColdFusion. Its APSB26-68 bulletin adds that ColdFusion 2025 Update 9 and earlier, and ColdFusion 2023 Update 20 and earlier, are affected. Akamai described the flaw as a path traversal issue in the RDS FILEIO controller exposed through the endpoint /CFIDE/main/ide.cfm?ACTION=FILEIO, with the ability to enable unauthorized file access and remote code execution.

Other alerts in the region

ECUCERT published alert Al-2026-0036 in July 2026 on the Wallstreet ransomware, which it describes as a double-extortion actor that encrypts systems and threatens to leak stolen data to increase pressure on victims. The agency recommended hardening and monitoring measures for organizations in Ecuador.

In the same alert, ECUCERT says, without confirmation, that the group may exploit known vulnerabilities and missing patching to gain initial access to corporate networks, although it did not list specific CVEs. In parallel, Help Net Security reported that CISA added CVE-2026-48282 to its Known Exploited Vulnerabilities catalog and ordered U.S. civilian federal agencies to remediate it before July 10, 2026. That coverage also said the exploit requires RDS to be enabled on the ColdFusion server and RDS authentication to be disabled.

Sources

View all