logo

Cleopatra’s Shadow: A Mass Exploitation Campaign Deploying a Java Backdoor Through Zero-Day Exploitation of Cleo MFT Software

ID: 7eb51b04-4724-5f87-b67d-fe0af0eba77a

STIX ID: report--7eb51b04-4724-5f87-b67d-fe0af0eba77a

Feed Name: Arctic Wolf

Threat Score
78/100

Date Published: 2024-12-12

Date Updated: 2026-07-25

Author: Stefan Hostetler, Julian Tuin, Aaron Diaz, Jon Grimm, and Cole Bosma

...
...

Arctic Wolf Labs observed an ongoing mass exploitation campaign targeting Cleo MFT products that leverages the autorun feature to drop obfuscated PowerShell/Bash stagers which fetch a Java loader and ultimately deploy a cross-platform Java backdoor called 'Cleopatra'; the report provides timeline, technical analysis of the stager/loader/backdoor, IoCs (multiple C2 IPs, filenames, SHA256), TTP mappings, and detection and remediation recommendations including patching to Cleo 5.8.0.24 and monitoring for obfuscated PowerShell activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.