logo

Hackers Exploit Quest KACE SMA Flaw to Harvest Credentials

ID: 4ed2189b-1430-5afe-85ef-cb75ca6c45bb

STIX ID: report--4ed2189b-1430-5afe-85ef-cb75ca6c45bb

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-03-23

Date Updated: 2026-04-22

Author: Divya

...
...

Security researchers observed active exploitation of CVE-2025-32975 (SSO authentication bypass) against unpatched Quest KACE SMA appliances beginning the week of March 9, 2026. Attackers obtain admin-level control, execute Base64-encoded payloads via KPluginRunProcess, download additional malware from 216.126.225.156, create unauthorized administrator accounts using runkbot.exe, deploy persistent PowerShell backdoors, harvest credentials with Mimikatz (renamed asd.exe), and pivot via RDP to critical infrastructure including domain controllers and backup servers; administrators are advised to apply specified patches and remove public internet exposure of KACE SMA interfaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.