Do Tigers Really Change Their Stripes?
ID: a72b390e-4fed-5b7e-a9cb-553309139f42
STIX ID: report--a72b390e-4fed-5b7e-a9cb-553309139f42
Feed Name: Huntress Blog
Huntress observed multiple April 2025 incidents where threat actors exploited CrushFTP (CVE-2025-31161) and Gladinet CentreStack/Triofox (CVE-2025-30406) vulnerabilities to deliver a malicious DLL (d3d11.dll), Mesh Agent remote management software, and an executable (Centre.exe) that was detected as Cobalt Strike; recurring IOCs include IP 2.58.56.16 and rtb.mftadsrvr.com, and the report recommends asset inventory, patching, attack-surface reduction, and comprehensive endpoint monitoring and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
