Over 200 Magento Stores Compromised In Rootkit Rampage via Zero-Day Exploit
ID: 60cdecc4-92c8-5feb-ba17-d46606aa2abf
STIX ID: report--60cdecc4-92c8-5feb-ba17-d46606aa2abf
Feed Name: GBHackers
Threat Score
Active exploitation of CVE-2025-54236 (“SessionReaper”) against unpatched Magento Commerce installations has been observed: actors scanned ~1,460 exposed Magento APIs, fully compromised 216 sites (root access), deployed web shells and likely rootkits for persistence, and published logs and /etc/passwd-like dumps; reported C2 IPs include 93.152.230.161 (Finland) and 115.42.60.163 (Hong Kong).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
