logo

2.5 Million+ Malicious Request From Hackers Attacking Adobe ColdFusion Servers

ID: a53b2771-26e9-5f62-9d80-43152e748b08

STIX ID: report--a53b2771-26e9-5f62-9d80-43152e748b08

Feed Name: cybersecurityNews.com

Threat Score
76/100

Date Published: 2025-12-29

Date Updated: 2026-04-21

Author: Abinaya

...
...

A single threat actor operating from Japan-based infrastructure conducted a large-scale exploitation campaign over the Christmas 2025 holiday, issuing more than 2.5 million malicious requests and focusing a ColdFusion phase that exploited 10+ critical CVEs; peak activity occurred on Christmas Day. The operation used ProjectDiscovery Interactsh/OAST domains for callback verification, deployed nearly 10,000 unique OAST domains, produced ~5,940 ColdFusion-targeted requests across 20 countries, and was driven largely from two CTG Server Limited IPs (134.122.136.119, 134.122.136.96). The campaign systematically scanned for 767 distinct CVEs (notable hits: CVE-2022-26134 and CVE-2014-6271), produced 4,118 unique JA4H HTTP signatures (suggesting template-based scanning like Nuclei), and is assessed as sophisticated initial-access reconnaissance preparing for downstream operations; recommended actions include blocking identified IPs/ASNs, deploying JA4+ detection signatures, and prioritizing ColdFusion/Java patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.