logo

Cleopatra’s Shadow: A Mass Exploitation Campaign Deploying a Java Backdoor Through Zero-Day Exploitation of Cleo MFT Software

ID: 966d2da5-3bb7-57d6-9fc5-9ef3ee72fb0b

STIX ID: report--966d2da5-3bb7-57d6-9fc5-9ef3ee72fb0b

Feed Name: Arctic Wolf

Threat Score
75/100

Date Published: 2024-12-12

Date Updated: 2026-07-25

Author: Stefan Hostetler, Julian Tuin, Aaron Diaz, Jon Grimm, and Cole Bosma

...
...

Arctic Wolf Labs observed a mass exploitation campaign (starting December 7, 2024 and ongoing) targeting Cleo MFT products to drop an obfuscated PowerShell/Bash stager that downloads a Java loader and a Java-based backdoor named 'Cleopatra'. The backdoor supports cross-platform operations, in-memory file storage, Cleo-specific discovery (parsing conf/Top.xml and conf/Options.xml), remote shell execution, disk file I/O, and implements evasion techniques (overwriting and deleting the initial JAR). The report provides timelines, attack mechanics, TTP mapping, numerous C2 IP IoCs, detection recommendations, and remediation advice including upgrading Cleo to fixed versions and monitoring for obfuscated PowerShell and unusual Java child processes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.