From Backup to Backdoor: Exploitation of CVE-2022-36537 in R1Soft Server Backup Manager
ID: 1fc9ca19-52b7-5f1a-9d3e-b3c9cf334790
STIX ID: report--1fc9ca19-52b7-5f1a-9d3e-b3c9cf334790
Feed Name: Fox-IT blog
Fox-IT describes an active, widespread exploitation campaign (starting late Nov 2022) that leverages CVE-2022-36537 in the ZK Java Framework to upload malicious JDBC drivers to ConnectWise R1Soft Server Backup Manager, which register a web shell (Godzilla-derived) at /zkau/jquery enabling command execution, lateral control of connected backup agents, and data exfiltration; the report includes IoCs (IP addresses and jar artifacts), Snort/Suricata detection rules, MITRE mappings, timelines, and observed impact (hundreds of backdoored servers, with 128 remaining as of 2023-03-03).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
