logo

Cleopatra’s Shadow: A Mass Exploitation Campaign Deploying a Java Backdoor Through Zero-Day Exploitation of Cleo MFT Software

ID: efccf290-d7f3-5ac3-865a-1747b59b989d

STIX ID: report--efccf290-d7f3-5ac3-865a-1747b59b989d

Feed Name: Arctic Wolf Blog

Threat Score
78/100

Date Published: 2024-12-12

Date Updated: 2026-04-27

...
...

Arctic Wolf Labs observed a widespread, ongoing campaign (starting 2024-12-07) exploiting Cleo Managed File Transfer products via the autorun feature to drop an obfuscated PowerShell stager that retrieves a Java loader and a Java-based backdoor named "Cleopatra." The staged loader decodes an AES key from an environment variable, downloads and AES/CBC-decrypts the final payload into memory, and the backdoor supports cross-platform remote shell, in-memory file storage, Cleo-specific configuration parsing, and filesystem access; the report includes numerous C2 IP IoCs, details of the execution chain, TTP mappings, and detection/remediation guidance (including upgrading Cleo to 5.8.0.24).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.