logo

Vulnerabilities in HFS Servers Exploited by Hackers to Distribute Malware and Mine Monero

ID: c46637a1-19b5-5f63-a03c-87dbfd514908

STIX ID: report--c46637a1-19b5-5f63-a03c-87dbfd514908

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2024-07-05

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

Malicious actors are actively exploiting CVE-2024-23692 in Rejetto HTTP File Server (HFS) to execute arbitrary commands and compromise servers; observed post-exploitation activity includes deployment of XMRig coinminers, multiple RATs and backdoors (XenoRAT, Gh0stRAT, PlugX) and GoThief for data exfiltration. The vulnerability affects HFS versions up to 2.3m and has been exploited in the wild, prompting advisories to update affected installations and monitor for indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.