CVE-2023-47246
ID: 217821c8-c66b-57aa-8559-3c2c220a65cf
STIX ID: report--217821c8-c66b-57aa-8559-3c2c220a65cf
Feed Name: Zscaler Security Research Blog
Threat Score
Attackers exploited the SysAid CVE-2023-47246 path traversal to upload a WAR webshell to the Tomcat webroot, used PowerShell to install and launch the GraceWire loader which decrypts a .bin payload and injects a trojan into processes (spoolsv.exe, msiexec.exe, svchost.exe), and executed cleanup scripts to remove evidence; the report also links related exploitation activity (CobaltStrike download command and CL0P references) and provides actionable IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
