Operation Open Ledger: AI-Assisted Crew Stole ERP Data from Spanish SMBs
Summary
Huntback’s threat-intelligence report examines Operation Open Ledger, an intrusion campaign targeting 10 Spanish small and mid-sized businesses. Researchers recovered 10,428 files from an internet-exposed server, including shell history, exfiltration scripts, exploit modules, credentials and 15 GB of stolen data. The main theft path began with an Azure service-principal secret found in an exposed Git repository: the operators minted OAuth tokens and used the Microsoft Dynamics 365 Business Central REST API to bulk-export customers, ledgers, invoices and, in some cases, attachments. The largest individual victim accounted for 6.6 GB. A parallel intrusion path used bespoke modules against six enterprise products, then moved through Active Directory with tools such as Mimikatz, DCSync, BloodHound, Impacket and Certipy. The report says the operator installed and drove the opencode AI coding agent, while the assembled toolkit included public proof-of-concepts in English, Russian and Chinese; one SmarterMail PoC credited ChatGPT. It describes this as evidence of AI-assisted assembly, not proof that an AI system authored the operation. The recovered material also included Sliver, Havoc and Cobalt Strike components, tunneling tools and an XMRig miner. Huntback attributes the infrastructure to a Russian-speaking operator or crew, while cautioning that language and artifacts do not identify a named group or state. The report recommends rotating exposed credentials, restricting Business Central API access, patching the weaponized appliances and disrupting the Active Directory attack chain.