logo

Cleo Malichus Malware Analysis CVE-2024-55956| Huntress

ID: 6d279489-6f8d-5c6c-ba03-226bc57b0ebd

STIX ID: report--6d279489-6f8d-5c6c-ba03-226bc57b0ebd

Feed Name: Huntress Blog

Threat Score
85/100

Date Published: 2024-12-11

Date Updated: 2026-04-28

...
...

This report analyzes "Malichus," a modular Java-based backdoor actively delivered by exploitation of a Cleo software zero-day (CVE-2024-55956). Huntress documents a three-stage chain—PowerShell loader, AES-encrypted Java downloader, and a multi-class Java post-exploitation framework with custom C2, file exfiltration, and interactive shell capabilities—providing technical details, custom C2 protocol description, IOCs (filenames and SHA256s) and links to YARA rules to support detection and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.