logo

Targeted attacks on Australian Networks

ID: c4fdac3f-d033-538b-af89-afa4347d0d4d

STIX ID: report--c4fdac3f-d033-538b-af89-afa4347d0d4d

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

### Executive Summary The ACSC/Zscaler advisory outlines an active campaign dubbed "Copy-paste compromises" targeting Australian networks that exploits multiple known RCE and deserialization vulnerabilities (Telerik, SharePoint, Citrix ADC/Gateway, IIS/.NET) via weaponized documents and public proof-of-concept code to deploy downloader and remote-access payloads (PowerShell Empire, HTTPCore/HTTPotato, CobaltStrike); the advisory lists affected products, mitigation steps (patching, disable macros), and detection signatures provided by Zscaler.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.