CVE-2024-36401 Exploited in Stealthy Bandwidth-Monetization Campaign
ID: 00794f7a-057e-5589-901b-4af2f5e6a740
STIX ID: report--00794f7a-057e-5589-901b-4af2f5e6a740
Feed Name: securityonline.info
Unit 42 reports an active campaign exploiting CVE-2024-36401 (GeoServer Apache Commons JXPath RCE, CVSS 9.8) in which attackers gain remote code execution to deploy lightweight executables and repurposed passive-income SDKs that quietly monetize victims' internet bandwidth; the campaign (tracked across March–April 2025) uses multiple staging servers and Transfer.sh, targets 7,000+ exposed GeoServer instances worldwide, and emphasizes stealth and persistence rather than high-resource malware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
