Cleo Malichus Malware Analysis CVE-2024-55956| Huntress
ID: 6d279489-6f8d-5c6c-ba03-226bc57b0ebd
STIX ID: report--6d279489-6f8d-5c6c-ba03-226bc57b0ebd
Feed Name: Huntress Blog
This report analyzes "Malichus," a modular Java-based backdoor actively delivered by exploitation of a Cleo software zero-day (CVE-2024-55956). Huntress documents a three-stage chain—PowerShell loader, AES-encrypted Java downloader, and a multi-class Java post-exploitation framework with custom C2, file exfiltration, and interactive shell capabilities—providing technical details, custom C2 protocol description, IOCs (filenames and SHA256s) and links to YARA rules to support detection and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
