216.73.217.80

Threat Actors Use CVE-2019-18935 to Deliver Reverse Shells and JuicyPotatoNG

· Published 31/01/2025 11:54 · Modified 31/01/2025 14:07

Export JSON

Essential information

Published
31/01/2025 11:54
Modified
31/01/2025 14:07
Tags
2025-01-31 CVE-2019-18935 iis juicypotatong privilege-escalation
Related entities
1 vulnerabilities (cve), 4 observables, 8 techniques (mitre)

Description

In early January 2025, a threat actor was observed exploiting in Progress Telerik UI for ASP.NET AJAX. The attacker used the worker process to load a reverse shell and execute reconnaissance commands. The infection process involved confirming the availability of the file upload handler and exploiting the vulnerability to upload and execute a remote shell. The reverse shell, a mixed-mode .NET assembly, connected to a C2 server and redirected cmd.exe input/output to the attacker. Post-exploitation activities included user enumeration and the deployment of the privilege escalation tool. The attack highlights the continued exploitation of older vulnerabilities and emphasizes the importance of timely patching and robust security measures.

External references