Active Exploitation of New Apache Struts Vulnerability CVE-2018-11776 Deploys Cryptocurrency Miner
ID: fa457811-d718-5be4-b818-a15ed4c8533a
STIX ID: report--fa457811-d718-5be4-b818-a15ed4c8533a
Feed Name: Volexity Blog
**Executive Summary:** Volexity observed active exploitation of Apache Struts CVE-2018-11776 beginning August 2018 where attackers leveraged a public PoC to achieve remote code execution and install CNRig cryptomining software; the report includes the exploit HTTP request, the upcheck.sh installer (which fetches multi-architecture ELF miners), malicious IPs, mining pool and account, and Suricata/Snort detection signatures, and recommends immediate patching to Struts 2.3.35 / 2.5.17 and limiting external exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
