216.73.216.6

Unmasking the new persistent attacks on Japan

· Published 06/03/2025 19:25 · Modified 06/03/2025 22:52

Export JSON

Essential information

Published
06/03/2025 19:25
Modified
06/03/2025 22:52
Tags
2025-03-06 CVE-2024-4577 cobalt strike credential-theft japan persistence php-cgi powershell taowu
Related entities
1 vulnerabilities (cve), 3 observables, 10 techniques (mitre), 1 malware, 5 others

Description

An unknown attacker has been targeting organizations in since January 2025, exploiting , a remote code execution vulnerability in on Windows. The attacker uses the kit '' for post-exploitation activities, including reconnaissance, privilege escalation, establishment, and credential theft. Targeted sectors include technology, telecommunications, entertainment, education, and e-commerce. The attack involves exploiting the vulnerability, executing scripts, and using various tools for system compromise. The attacker's techniques are similar to those of the 'Dark Cloud Shield' group, but attribution remains uncertain. A pre-configured installer script found on the C2 server deploys multiple adversarial tools and frameworks, indicating potential for future attacks.

External references