logo

Your Connection, Their Cash: Threat Actors Misuse SDKs to Sell Your Bandwidth

ID: 04c8cfb2-7a61-5e90-b83e-ee9eaa3a965d

STIX ID: report--04c8cfb2-7a61-5e90-b83e-ee9eaa3a965d

Feed Name: Palo Alto Networks Unit 42

Threat Score
78/100

Date Published: 2025-08-21

Date Updated: 2026-04-28

Author: Zhibin Zhang, Yiheng An, Chao Lei and Haozhe Zhang

...
...

Palo Alto Networks Unit 42 observed an active campaign (since March 2025) exploiting CVE-2024-36401 in GeoServer to achieve remote code execution and deploy scripts/executables that install or misuse legitimate SDKs and apps to covertly monetize victims' bandwidth (residential proxy/network sharing). The report details exploit code flow through JXPath, infrastructure shifts (notable distribution hosts 37.187.74.75 and 64.226.112.52 and exploit source 185.246.84.189), numerous IOCs (IPs, ports, URLs, SHA256 hashes), and recommends patching and using detections/controls (Threat Prevention, WildFire, XDR) to mitigate the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.