Unmasking the new persistent attacks on Japan
ID: f66861bf-69e7-574c-a1c8-eeb08f9eda39
STIX ID: report--f66861bf-69e7-574c-a1c8-eeb08f9eda39
Feed Name: Cisco Talos
Cisco Talos documents an active campaign (since Jan 2025) targeting organizations in Japan that leverages CVE-2024-4577 (PHP-CGI RCE) to execute PowerShell downloaders that inject Cobalt Strike reverse HTTP beacons; operators then use TaoWu Cobalt Strike plugins and public tools (JuicyPotato/SweetPotato/RottenPotato, Ladon, SharpTask, SharpGPOAbuse, fscan, Seatbelt, Mimikatz) to escalate privileges, establish persistence, perform lateral movement, and exfiltrate credentials, while hosting C2 and preconfigured attack tooling on Alibaba cloud with exposed repositories and published IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
