[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fjBHnumBCh2rFlj5yGsHCgx-AABmT6NiHw-XS4HqEvLw":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"33159f28-356b-4a8b-b206-2d3ef267b865","hardcoded-credentials-enable-persistent-malware-control","ebccef28-fbeb-4d6f-a750-6b27a08ce4d9","Hardcoded Credentials Enable Persistent Malware Control","The Bissa scanner malware demonstrates the critical security risk of hardcoded credentials in malicious software. By embedding a Telegram bot token directly in the runner scripts, attackers maintained persistent command and control capabilities that could survive system reboots and basic cleanup efforts. This technique allows threat actors to remotely control infected systems through popular messaging platforms, making detection more challenging as the traffic appears as legitimate social media communication. Organizations must implement robust monitoring and configuration management to detect such embedded credentials and unauthorized communication channels.","**Immediate actions:**\n- Scan all systems for the specific Telegram bot token (bissapwned_bot, ID 8798206332)\n- Block communication to known malicious Telegram bot APIs at network perimeter\n- Review and quarantine any detected Bissa scanner artifacts\n\n**Detection measures:**\n- Deploy network monitoring to identify unusual outbound connections to messaging platforms\n- Implement static code analysis tools to scan for hardcoded tokens and credentials\n- Monitor for unexpected bot-like communication patterns in network traffic\n\n**Long-term improvements:**\n- Establish baseline network behavior monitoring to detect anomalous C2 communications\n- Implement application allowlisting to prevent unauthorized script execution\n- Create incident response procedures specifically for credential-based persistence mechanisms",[12,13,14,15,16],"CIS Control 11","CIS Control 13","NIST SC-7","NIST SI-4","NIST CM-2","published","2026-04-23T13:09:50.371942+00:00","2026-04-23T13:09:49.998+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fx.com\u002FTheDFIRReport\u002Fstatus\u002F2047288992945647903","beyond-the-ai-control-surface-the-host-also-preserved-the-operator-s-alerting-an-237b42","\"Beyond the AI-control surface, the host also preserved the operator’s alerting and command chann...",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":32,"name":33,"slug":34,"description":35,"color":36},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]