Your Connection, Their Cash: Threat Actors Misuse SDKs to Sell Your Bandwidth
ID: 04c8cfb2-7a61-5e90-b83e-ee9eaa3a965d
STIX ID: report--04c8cfb2-7a61-5e90-b83e-ee9eaa3a965d
Feed Name: Palo Alto Networks Unit 42
Date Published: 2025-08-21
Date Updated: 2026-04-28
Author: Zhibin Zhang, Yiheng An, Chao Lei and Haozhe Zhang
Palo Alto Networks Unit 42 observed an active campaign (since March 2025) exploiting CVE-2024-36401 in GeoServer to achieve remote code execution and deploy scripts/executables that install or misuse legitimate SDKs and apps to covertly monetize victims' bandwidth (residential proxy/network sharing). The report details exploit code flow through JXPath, infrastructure shifts (notable distribution hosts 37.187.74.75 and 64.226.112.52 and exploit source 185.246.84.189), numerous IOCs (IPs, ports, URLs, SHA256 hashes), and recommends patching and using detections/controls (Threat Prevention, WildFire, XDR) to mitigate the threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
