logo

Cleo’s trojan horse.

ID: 59e87073-aee4-52cb-89ac-c6937f42145a

STIX ID: report--59e87073-aee4-52cb-89ac-c6937f42145a

Feed Name: The CyberWire

Threat Score
85/100

Date Published: 2025-02-08

Date Updated: 2026-04-23

...
...

Arctic Wolf Labs discovered an ongoing mass exploitation campaign ("Cleopatra’s Shadow") starting December 7, 2024, targeting Cleo Managed File Transfer products; attackers used a malicious PowerShell stager to deploy a Java backdoor named Cleopatra that offers in-memory file storage and cross-platform persistence on Windows and Linux, and leveraged an autorun-based bypass despite Cleo's prior CVE-2024-50623 patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.