Threat Campaign Targeting Cleo MFT Products - Remediation Guidance
ID: 5596f92c-93c4-54be-9914-0a6ef0489c90
STIX ID: report--5596f92c-93c4-54be-9914-0a6ef0489c90
Feed Name: Arctic Wolf Blog
Arctic Wolf Labs observed an active campaign (first indications Oct 19, spike in Dec 2024) targeting Cleo MFT products (Harmony, VLTrader, LexiCom), where threat actors are suspected to leverage a remote code execution vulnerability (CVE-2024-50623) or similar flaws to run malicious PowerShell via the Autorun feature, drop and execute JAR payloads, and perform system reconnaissance; the bulletin provides detection context, mitigation steps (patching, disabling/hardening Autorun), and a list of suspicious files/IOCs to remove.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
