logo

PHP-CGI Vulnerability Exploited in Attacks Targeting Japan (Campaign)

ID: 40f1f41f-331e-567b-a165-0dbc171d9bab

STIX ID: report--40f1f41f-331e-567b-a165-0dbc171d9bab

Feed Name: Wiz Cloud Threat Landscape

Threat Score
82/100

Date Published: 2025-03-06

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Researchers identified an active campaign targeting organizations across Japanese sectors that leverages CVE-2024-4577 (PHP-CGI RCE on Windows) to achieve remote code execution and retrieve Cobalt Strike shellcode via PowerShell. The attackers use sophisticated post-exploitation TTPs — Potato privilege escalation (Juicy/Sweet/RottenPotato), persistence (registry modifications, scheduled tasks, malicious services via sharpTask/SharpStay/SharpHide), reconnaissance (fscan, Seatbelt), GPO abuse (SharpGPOAbuse) and credential theft (Mimikatz) — with tool hosting observed on Alibaba Cloud.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.