A critical remote code execution flaw in OSGeo GeoServer GeoTools (CVE-2024-36401, CVSS score: 9.8) is being exploited in multiple malware campaigns. Threat actors are leveraging the vulnerability to deliver cryptocurrency miners, botnet malware like Condi and JenX, and a known Linux backdoor called SideWalk.
The vulnerability has been actively exploited since July 2024, targeting IT service providers, technology companies, government entities, and telecommunications sectors across India, the U.S., Belgium, Thailand, and Brazil.
Key Findings:
- The flaw has been used to deliver GOREVERSE, a reverse proxy server for post-exploitation activities.
- The attacks include using Fast Reverse Proxy (FRP) to establish encrypted tunnels for persistent access, data exfiltration, and further payload delivery.
- The SideWalk backdoor, attributed to APT41, is a significant component of the attack chain, impacting ARM, MIPS, and X86 architectures.
- The campaigns span South America, Europe, and Asia, highlighting the global reach of these sophisticated attacks.
Recommendations:
- Patch vulnerable GeoServer instances immediately.
- Monitor for any signs of exploitation, including unusual traffic patterns or unauthorized proxy usage.