logo

Unmasking the new persistent attacks on Japan

ID: f66861bf-69e7-574c-a1c8-eeb08f9eda39

STIX ID: report--f66861bf-69e7-574c-a1c8-eeb08f9eda39

Feed Name: Cisco Talos

Threat Score
78/100

Date Published: 2025-03-06

Date Updated: 2026-04-27

Author: Chetan Raghuprasad

...
...

Cisco Talos documents an active campaign (since Jan 2025) targeting organizations in Japan that leverages CVE-2024-4577 (PHP-CGI RCE) to execute PowerShell downloaders that inject Cobalt Strike reverse HTTP beacons; operators then use TaoWu Cobalt Strike plugins and public tools (JuicyPotato/SweetPotato/RottenPotato, Ladon, SharpTask, SharpGPOAbuse, fscan, Seatbelt, Mimikatz) to escalate privileges, establish persistence, perform lateral movement, and exfiltrate credentials, while hosting C2 and preconfigured attack tooling on Alibaba cloud with exposed repositories and published IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.