logo

Do Tigers Really Change Their Stripes?

ID: a72b390e-4fed-5b7e-a9cb-553309139f42

STIX ID: report--a72b390e-4fed-5b7e-a9cb-553309139f42

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2025-05-06

Date Updated: 2026-04-28

...
...

Huntress observed multiple April 2025 incidents where threat actors exploited CrushFTP (CVE-2025-31161) and Gladinet CentreStack/Triofox (CVE-2025-30406) vulnerabilities to deliver a malicious DLL (d3d11.dll), Mesh Agent remote management software, and an executable (Centre.exe) that was detected as Cobalt Strike; recurring IOCs include IP 2.58.56.16 and rtb.mftadsrvr.com, and the report recommends asset inventory, patching, attack-surface reduction, and comprehensive endpoint monitoring and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.