216.73.217.22

Novel Use of "mount" Spotted in Hikvision Attacks

· Published 24/07/2025 19:44 · Modified 24/07/2025 20:40

Export JSON

Essential information

Published
24/07/2025 19:44
Modified
24/07/2025 20:40
Tags
2025-07-24 CVE-2021-36260 command injection go-exploit gtfobin hikvision mirai mount nfs
Related entities
1 vulnerabilities (cve), 6 observables, 1 malware

Description

Attackers are exploiting , a vulnerability in devices, using a novel technique involving the '' command as a . This method allows them to a remote share and execute malicious files, bypassing common network signatures. The technique has been added to VulnCheck's framework. The attacks originate from specific IP addresses and utilize -like payloads. Over one million potentially vulnerable internet-facing targets are still exposed, making this exploit highly viable for internal pivots or building proxy networks. Advanced threat actors like Flax Typhoon and Fancy Bear have been associated with exploiting this vulnerability.

External references