logo

Hackers targeting WhatsUp Gold with public exploit since August

ID: 5b5c27b0-76f0-5c84-aa64-1067039fb675

STIX ID: report--5b5c27b0-76f0-5c84-aa64-1067039fb675

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-09-12

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Hackers are actively exploiting two SQL injection vulnerabilities in Progress Software's WhatsUp Gold (CVE-2024-6670 and CVE-2024-6671) to bypass authentication, obtain administrator passwords, and achieve remote code execution via Active Monitor PowerShell scripts; attackers then use msiexec to install multiple RATs (Atera Agent, Radmin, SimpleHelp, Splashtop) to establish persistence. PoC exploit code was published Aug 30 and Trend Micro telemetry observed exploitation within hours, while patches were released by the vendor on Aug 16—unpatched systems remain at high risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.