216.73.216.226

Cleopatra's Shadow: A Mass Exploitation Campaign Deploying a Java Backdoor Through Zero-Day Exploitation of Cleo MFT Software

· Published 13/12/2024 12:40 · Modified 13/12/2024 15:59

Export JSON

Essential information

Published
13/12/2024 12:40
Modified
13/12/2024 15:59
Tags
2024-12-13 CVE-2024-50623 cleo mft cleopatra
Related entities
6 techniques (mitre)

Description

A mass exploitation campaign targeting Cleo Managed File Transfer (MFT) products was observed in December 2024. The attackers exploited a zero-day vulnerability to deploy a Java-based backdoor dubbed . The campaign began on December 7 and is ongoing. The attack chain involves an obfuscated PowerShell stager, a Java loader, and the backdoor. The backdoor supports cross-platform functionality on Windows and Linux, with specific features to access data within software. Multiple IP addresses were used for command and control, while vulnerability scanning originated from only two IPs. The campaign appears opportunistic, affecting various industries. Affected Cleo products include Harmony, VLTrader, and LexiCom, even on patched versions.

External references