AhnLab Security Intelligence Center (ASEC) reports that unpatched GeoServer instances are still being attacked due to a serious Remote Code Execution (RCE) vulnerability, CVE-2024-36401. GeoServer, a Java-based open-source GIS server, became a target after a flaw was found in early 2024. This vulnerability lets unauthorized users run any code on affected systems, leading to potential malware attacks. In September 2024, Fortinet reported that attackers were using this vulnerability to spread malware like GOREVERSE, SideWalk, Mirai, Condi, and CoinMiner. Trend Micro also found that the Earth Baxia group targeted a Taiwanese government agency with spear-phishing attacks exploiting the same flaw, showing the global impact. South Korea has become a major target, with ASEC noting infections in Windows systems running vulnerable GeoServer versions. Exploiting CVE-2024-36401 probably allowed attackers to run PowerShell commands to install NetCat, a flexible networking tool often used as a reverse shell for remotely controlling compromised systems. After the initial breach, attackers in South Korea deployed XMRig, a well-known cryptocurrency miner that hijacks system resources to mine Monero coins. In Windows systems, PowerShell scripts from malicious URLs started the installation, while in Linux systems, Bash scripts likely did the same, including stopping other miner processes and ensuring persistence with Cron jobs linked to Pastebin-hosted scripts. This dual-OS targeting shows the attackers' sophistication, adapting their methods to the victim's environment for maximum impact. Installing CoinMiner not only slows down system performance but also opens the door to further malicious activities like data theft or more malware through the NetCat backdoor. ASEC's report stresses the urgent need for organizations to patch their systems, as these attacks continue, exploiting unpatched GeoServer instances in various regions and sectors.
Russian state-sponsored cyber actors are actively targeting vulnerable and poorly secured network routers to gain unauthorized access to organizations, particularly those operating...
A recent wire-level analysis conducted on Grok Build CLI version reported that the tool automatically transmitted complete Git repositories, including unread files and commit histo...
A new software supply chain campaign has compromised several AsyncAPI npm packages to distribute a remote access trojan called Miasma v3. The affected packages include @asyncapi/ge...