Stealthy “City Forum” Attacks Target Salesforce and ServiceNow Using Custom Toolset

Stealthy “City Forum” Attacks Target Salesforce and ServiceNow Using Custom Toolset

Reco is pursuing a sophisticated and innovative campaign targeting both Salesforce and ServiceNow through a seemingly bespoke multi-platform toolset.

Researchers believe that the main targets include telecommunications, banking and financial services companies, enterprise software providers (including security and data protection companies) and public sector portals.

The campaign is called “City Forum’. It targets both Salesforce Aura and the newer LWR implementations, which is the first actual observed exploitation of Salesforce’s UI API guest interface. Additionally, attacks on Aura (which are essential to include in a Salesforce campaign since the number of Aura users is still larger than LWR users) are integrated with the LWR attacks in a single toolset.

“One Go Binary hit Salesforce through Aura and LWR and hit ServiceNow from the same box,” the researchers comment in one Blog report. This is consistent with a custom toolset and not standard products like AuraInspector.

The primary access key for both platforms is the guest user. Each Salesforce Experience Cloud has its own guest user in which an unauthenticated request works. ServiceNow is similar. “You can’t delete these guest users, and requiring a login doesn’t remove them – the profile, its permissions, its sharing rules, and any code that runs in its context are all still there. If the guest can read a record, so can anyone on the Internet.”

To better understand the level of innovation in this campaign, it is useful to compare the City Forum campaign to other attacks targeting Aura – particularly ShinyHunters’ Salesforce Aura campaign released in March 2026. In addition to attacking LWR in Salesforce, “(City Forum) is attacking a native ServiceNow Service Portal search endpoint that has almost no online documentation or known open source tools.”

Advertising. Scroll to continue reading.

ShinyHunters only targeted Aura in Salesforce (no known targeting of ServiceNow) and used a modified version of the existing AuraInspector. City-Forum uses a new custom multiplatform toolset.

Reco takes pains to explain that it doesn’t rule out that ShinyHunters is also behind City-Forum, adding: “We don’t know who that is and we’re not ruling anyone out or in.”

The City Forum campaign uses a single machine. “The same IP has carried the same domain since March 2025 and is still scanning today – at one address for at least seventeen months, with no rotation at any point.” This IP (158.220.87.79) resolves to city-forum.com.

Reco does not draw any conclusions from this, but the main advantage of a single machine is that it reduces the attacker’s footprint on anomaly detection systems. It may be easier to block if it is known, but harder to detect if it is done secretly.

The campaign targets unauthenticated guest user access in Salesforce and ServiceNow. However, converting to an authenticated user in Salesforce would be possible if self-registration is enabled. There is no similar mechanism for ServiceNow.

It is not necessary to be an authenticated guest user, but could allow access to more sensitive data. Because many organizations misconfigure guest permissions, the possibility still exists. However, “So far we have only seen guest user activity – never an authenticated user, but we cannot rule it out,” the researchers comment.”

Aura shares the majority of Salesforce data collected and exfiltrated. “The busiest target logged over 560,000 events… across the entire campaign window, essentially exclusively guest aura enumerations,” the researchers say. GraphQL is also used to pull data from the Salesforce LWR sites.

The ServiceNow attack targets the virtually undocumented search endpoint. This is used to identify essential content. “The Output Length column is worth a look while you’re here: rows that return significantly more than the small baseline of empty results are queries that returned with content.” The attacker can draw from the most likely outcomes.

The exfiltration is not noisy – it is high volume but is per protocol. This makes detection more difficult and potentially confirms the stealth intent behind using a single constant destination address.

As with the ShinyHunters attack, there is no evidence of a breach of the Salesforce or ServiceNow platforms. “Every byte the attacker retrieved was something that a website owner had made available to anonymous users.”

Being targeted by City-Forum is not a loud, easily recognized attack. But most things can be found if you know where to look. The Reco research blog contains detailed IOCs and remediation instructions. At the very least, make sure that self-registration is not enabled as soon as possible. This prevents an unauthenticated guest from attempting to upgrade to an authenticated guest.

Related: BeyondTrust and LastPass affected by Klue-Salesforce incident

Related: Salesforce instances hacked via Gainsight integrations

Related: Blackmail group leaks millions of records from Salesforce hacks

Related: Hackers blackmail Salesforce after stealing data from dozens of customers

Leave a Reply

Your email address will not be published. Required fields are marked *