logo

from-wso2-rce-to-ssh-lateral-movement (Incident)

ID: 4c7676de-f2cc-52d8-bbce-1b85dd8e6872

STIX ID: report--4c7676de-f2cc-52d8-bbce-1b85dd8e6872

Feed Name: Wiz Cloud Threat Landscape

Threat Score
70/100

Date Published: 2023-06-05

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

CrowdStrike observed an incident where an unknown actor exploited a WSO2 remote code execution vulnerability (CVE-2022-29464) to compromise Linux-based cloud systems, install cryptominers and webshells (using timestomping to hide them), scan the local network for discovery, search for cloud credentials in /etc/shadow and shell history, and attempt lateral movement via SSH.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.