Hackers Exploit Quest KACE SMA Flaw to Harvest Credentials
ID: 4ed2189b-1430-5afe-85ef-cb75ca6c45bb
STIX ID: report--4ed2189b-1430-5afe-85ef-cb75ca6c45bb
Feed Name: GBHackers
Security researchers observed active exploitation of CVE-2025-32975 (SSO authentication bypass) against unpatched Quest KACE SMA appliances beginning the week of March 9, 2026. Attackers obtain admin-level control, execute Base64-encoded payloads via KPluginRunProcess, download additional malware from 216.126.225.156, create unauthorized administrator accounts using runkbot.exe, deploy persistent PowerShell backdoors, harvest credentials with Mimikatz (renamed asd.exe), and pivot via RDP to critical infrastructure including domain controllers and backup servers; administrators are advised to apply specified patches and remove public internet exposure of KACE SMA interfaces.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
