PHP-CGI Vulnerability Exploited in Attacks Targeting Japan (Campaign)
ID: 40f1f41f-331e-567b-a165-0dbc171d9bab
STIX ID: report--40f1f41f-331e-567b-a165-0dbc171d9bab
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-03-06
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Researchers identified an active campaign targeting organizations across Japanese sectors that leverages CVE-2024-4577 (PHP-CGI RCE on Windows) to achieve remote code execution and retrieve Cobalt Strike shellcode via PowerShell. The attackers use sophisticated post-exploitation TTPs — Potato privilege escalation (Juicy/Sweet/RottenPotato), persistence (registry modifications, scheduled tasks, malicious services via sharpTask/SharpStay/SharpHide), reconnaissance (fscan, Seatbelt), GPO abuse (SharpGPOAbuse) and credential theft (Mimikatz) — with tool hosting observed on Alibaba Cloud.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
