logo

MDR insights: defense against persistent threats and Oracle WebLogic CVE-2020-14882

ID: 9c18d285-1fe0-58cb-a639-a24d5b394cdc

STIX ID: report--9c18d285-1fe0-58cb-a639-a24d5b394cdc

Feed Name: Expel Blog

Threat Score
78/100

Date Published: 2024-11-12

Date Updated: 2026-04-27

Author: Aaron Walton

...
...

Expel observed multiple September 2024 intrusions where the criminal group Magnet Goblin exploited Oracle WebLogic CVE-2020-14882 to execute commands, download the NerBian RAT and various RMM tools (Panda, SimpleHelp, N‑Able, Level), create a persistence account (sqladmin), and hide access via Ligolo and Limenet infrastructure; the report provides file hashes, IPs/domains, and detection/remediation guidance to prioritize patching and hunt for unauthorized RMM tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.