Suspicious SmarterMail Force Password Reset API Request Indicating Account Takeover

PremiumReviewedSigma · High · v1
Category
webserver
Author
HuntRule
Published
2026-10-01
Updated
2026-10-01

ATT&CK techniques

Initial Access → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Execution

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects HTTP POST requests to the SmarterMail force-reset-password API endpoint, the account takeover primitive Huntress observed being abused to seize administrator accounts before achieving remote code execution. Attackers call this authenticated endpoint to reset a target user password and hijack the session. Requests to this path, particularly from scripted clients, indicate exploitation of the account takeover weakness.

Related detections9 linkedT1190 — drag to rearrange
Possible Next.js Middleware Auth Bypass via X-Middleware-Subrequest Header (CVE-2025-29927)
Windows Failed Logon (Event ID 4625) From Non-Private Public IP
Possible CrushFTP CVE-2025-31161 Authentication Bypass via Webserver
Suspicious SolarWinds Web Help Desk Java Process Spawning Command Shell
Malicious IIS Worker Process Spawning PowerShell via Gladinet CentreStack Exploit
Suspicious PowerShell Out-of-Band Request to Interactsh Domain
Exchange Worker Process Spawning Command Shell via OWASSRF
Suspicious PowerShell Spawned by SysAid Java Process
Suspicious Shell or Installer Spawned by ActiveMQ Java Process
Suspicious SmarterMail Force Password Reset API Request Indicating Account Takeover
Pivot detection · T1190 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.