from-wso2-rce-to-ssh-lateral-movement (Incident)
ID: 4c7676de-f2cc-52d8-bbce-1b85dd8e6872
STIX ID: report--4c7676de-f2cc-52d8-bbce-1b85dd8e6872
Feed Name: Wiz Cloud Threat Landscape
Threat Score
Date Published: 2023-06-05
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
...
...
CrowdStrike observed an incident where an unknown actor exploited a WSO2 remote code execution vulnerability (CVE-2022-29464) to compromise Linux-based cloud systems, install cryptominers and webshells (using timestomping to hide them), scan the local network for discovery, search for cloud credentials in /etc/shadow and shell history, and attempt lateral movement via SSH.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
