logo

Chinese Hackers Exploit Check Point VPN Zero-Day to Target Organizations Globally

ID: b78493bd-ed01-5759-aa1f-fb99582391d2

STIX ID: report--b78493bd-ed01-5759-aa1f-fb99582391d2

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2025-02-28

Date Updated: 2026-04-22

Author: Divya

...
...

Researchers link a cross-continental cyberespionage campaign (June 2024–Jan 2025) to Chinese state-sponsored actors who exploited a patched Check Point VPN vulnerability (CVE-2024-24919) to steal VPN credentials, conduct RDP/SMB lateral movement, and deploy ShadowPad malware (with opportunistic NailaoLocker ransomware use). The campaign primarily targeted manufacturing (60%+ of confirmed victims) across Germany, Brazil, South Africa, and India, used DLL sideloading (e.g., legitimate EXEs loading malicious DLLs from C:\PerfLogs), and left indicators such as the C2 domain update.grayshoal.com and IP 104.168.235.66; organizations were urged to apply the May 27, 2024 patches, reset VPN credentials, and hunt for anomalous logins and RDP activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.