Cleo’s trojan horse.
ID: 59e87073-aee4-52cb-89ac-c6937f42145a
STIX ID: report--59e87073-aee4-52cb-89ac-c6937f42145a
Feed Name: The CyberWire
Threat Score
Arctic Wolf Labs discovered an ongoing mass exploitation campaign ("Cleopatra’s Shadow") starting December 7, 2024, targeting Cleo Managed File Transfer products; attackers used a malicious PowerShell stager to deploy a Java backdoor named Cleopatra that offers in-memory file storage and cross-platform persistence on Windows and Linux, and leveraged an autorun-based bypass despite Cleo's prior CVE-2024-50623 patch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
