logo

Over 200 Magento Stores Compromised In Rootkit Rampage via Zero-Day Exploit

ID: 60cdecc4-92c8-5feb-ba17-d46606aa2abf

STIX ID: report--60cdecc4-92c8-5feb-ba17-d46606aa2abf

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-01-30

Date Updated: 2026-05-22

Author: Varshini

...
...

Active exploitation of CVE-2025-54236 (“SessionReaper”) against unpatched Magento Commerce installations has been observed: actors scanned ~1,460 exposed Magento APIs, fully compromised 216 sites (root access), deployed web shells and likely rootkits for persistence, and published logs and /etc/passwd-like dumps; reported C2 IPs include 93.152.230.161 (Finland) and 115.42.60.163 (Hong Kong).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.