ShadowSilk Data Exfiltration Attack
ID: bc9e1989-b668-503a-bf8c-dfe328823c17
STIX ID: report--bc9e1989-b668-503a-bf8c-dfe328823c17
Feed Name: FortiGuard Labs | FortiGuard Center - Outbreak Alerts
Threat Score
FortiGuard Labs observed an active ShadowSilk APT campaign exploiting Drupal and WP-Automatic vulnerabilities (CVE-2018-7600, CVE-2018-7602, CVE-2024-27956) to gain initial access, deploy web shells and utilities, and install RATs for lateral movement and large-scale data exfiltration targeting government organizations across Central Asia and the Asia-Pacific; customers are advised to patch immediately and engage incident response as needed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
