Hackers attack HFS servers to drop malware and Monero miners
ID: 315b8b7b-922c-55f9-bfbf-7ddd10d7ea9f
STIX ID: report--315b8b7b-922c-55f9-bfbf-7ddd10d7ea9f
Feed Name: Bleeping Computer
Threat Score
Researchers observed active exploitation of CVE-2024-23692 in Rejetto HFS 2.3m allowing unauthenticated command execution; attackers harvest system information, add administrative users, terminate the HFS process to lock out others, and deploy miners (XMRig) and multiple remote-access/backdoor malware (XenoRAT, Gh0stRAT, PlugX, GoThief), with at least one campaign linked to LemonDuck and IoCs published by ASEC.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
