Description

AhnLab Security Intelligence Center (ASEC) reports that unpatched GeoServer instances are still being attacked due to a serious Remote Code Execution (RCE) vulnerability, CVE-2024-36401. GeoServer, a Java-based open-source GIS server, became a target after a flaw was found in early 2024. This vulnerability lets unauthorized users run any code on affected systems, leading to potential malware attacks. In September 2024, Fortinet reported that attackers were using this vulnerability to spread malware like GOREVERSE, SideWalk, Mirai, Condi, and CoinMiner. Trend Micro also found that the Earth Baxia group targeted a Taiwanese government agency with spear-phishing attacks exploiting the same flaw, showing the global impact. South Korea has become a major target, with ASEC noting infections in Windows systems running vulnerable GeoServer versions. Exploiting CVE-2024-36401 probably allowed attackers to run PowerShell commands to install NetCat, a flexible networking tool often used as a reverse shell for remotely controlling compromised systems. After the initial breach, attackers in South Korea deployed XMRig, a well-known cryptocurrency miner that hijacks system resources to mine Monero coins. In Windows systems, PowerShell scripts from malicious URLs started the installation, while in Linux systems, Bash scripts likely did the same, including stopping other miner processes and ensuring persistence with Cron jobs linked to Pastebin-hosted scripts. This dual-OS targeting shows the attackers' sophistication, adapting their methods to the victim's environment for maximum impact. Installing CoinMiner not only slows down system performance but also opens the door to further malicious activities like data theft or more malware through the NetCat backdoor. ASEC's report stresses the urgent need for organizations to patch their systems, as these attacks continue, exploiting unpatched GeoServer instances in various regions and sectors.