THREATOPS
THREAT OPSThreat News › Turning Enterprise Update Servers Into Backdoor Factories (0_o) – Part 2

Turning Enterprise Update Servers Into Backdoor Factories (0_o) – Part 2

medspecteropsPublished 2026-08-05

<p class="wp-block-paragraph"><em><strong>TL;DR:</strong> When WSUS downloads files for updates, it requires the server to leverage the BITS protocol. WSUS normally requires executables to be digitally signed, however this can be bypassed by appending the <code>.esd</code> or <code>.txt</code> file extensions.</em></p>

<h2 class="wp-block-heading" id="h-introduction">Introduction</h2>

<p cla

Indicators of compromise

Original source: https://specterops.io/blog/2026/08/05/turning-enterprise-update-servers-into-backdoor-factories-part-2/