logo

MFT Exploitation and Adversary Operations

ID: a98b0ed6-c761-594e-898b-bdeabdad3efe

STIX ID: report--a98b0ed6-c761-594e-898b-bdeabdad3efe

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2024-04-12

Date Updated: 2026-04-28

...
...

Huntress analyzes CVE-2023-43177 in CrushFTP, a critical MFT vulnerability that enables full access to hosted files and arbitrary code execution across platforms; although a patch was released in August 2023, many internet-facing instances likely remain unpatched, creating substantial risk for data exfiltration and system takeover. The report situates this issue within continued adversary focus on MFT products (citing MoveIT/cl0p activity), emphasizes manual patching and configuration changes required, and advises layered defenses—restricting exposure, hardening configurations, and improving endpoint and network visibility—to detect and mitigate exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.