Cleopatra’s Shadow: A Mass Exploitation Campaign Deploying a Java Backdoor Through Zero-Day Exploitation of Cleo MFT Software
ID: 966d2da5-3bb7-57d6-9fc5-9ef3ee72fb0b
STIX ID: report--966d2da5-3bb7-57d6-9fc5-9ef3ee72fb0b
Feed Name: Arctic Wolf
Date Published: 2024-12-12
Date Updated: 2026-07-25
Author: Stefan Hostetler, Julian Tuin, Aaron Diaz, Jon Grimm, and Cole Bosma
Arctic Wolf Labs observed a mass exploitation campaign (starting December 7, 2024 and ongoing) targeting Cleo MFT products to drop an obfuscated PowerShell/Bash stager that downloads a Java loader and a Java-based backdoor named 'Cleopatra'. The backdoor supports cross-platform operations, in-memory file storage, Cleo-specific discovery (parsing conf/Top.xml and conf/Options.xml), remote shell execution, disk file I/O, and implements evasion techniques (overwriting and deleting the initial JAR). The report provides timelines, attack mechanics, TTP mapping, numerous C2 IP IoCs, detection recommendations, and remediation advice including upgrading Cleo to fixed versions and monitoring for obfuscated PowerShell and unusual Java child processes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
