logo

CVE-2024-36401 Exploited in Stealthy Bandwidth-Monetization Campaign

ID: 00794f7a-057e-5589-901b-4af2f5e6a740

STIX ID: report--00794f7a-057e-5589-901b-4af2f5e6a740

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2025-08-22

Date Updated: 2026-04-22

Author: Ddos

...
...

Unit 42 reports an active campaign exploiting CVE-2024-36401 (GeoServer Apache Commons JXPath RCE, CVSS 9.8) in which attackers gain remote code execution to deploy lightweight executables and repurposed passive-income SDKs that quietly monetize victims' internet bandwidth; the campaign (tracked across March–April 2025) uses multiple staging servers and Transfer.sh, targets 7,000+ exposed GeoServer instances worldwide, and emphasizes stealth and persistence rather than high-resource malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.