Skip to content

Secure IT

Stay Secure. Stay Informed.

Primary Menu
  • Home
  • Sources
    • Krebs On Security
    • Security Week
    • The Hacker News
    • Schneier On Security
  • Home
  • The Hacker News
  • PHP-CGI RCE Flaw Exploited in Attacks on Japan’s Tech, Telecom, and E-Commerce Sectors
  • The Hacker News

PHP-CGI RCE Flaw Exploited in Attacks on Japan’s Tech, Telecom, and E-Commerce Sectors

[email protected] The Hacker News Published: March 7, 2025 | Updated: March 7, 2025 2 min read
0 views

Mar 07, 2025Ravie LakshmananThreat Intelligence /Vulnerability

PHP-CGI RCE Flaw Exploited

Threat actors of unknown provenance have been attributed to a malicious campaign predominantly targeting organizations in Japan since January 2025.

“The attacker has exploited the vulnerability CVE-2024-4577, a remote code execution (RCE) flaw in the PHP-CGI implementation of PHP on Windows, to gain initial access to victim machines,” Cisco Talos researcher Chetan Raghuprasad said in a technical report published Thursday.

“The attacker utilizes plugins of the publicly available Cobalt Strike kit ‘TaoWu’ for-post exploitation activities.”

Targets of the malicious activity encompass companies across technology, telecommunications, entertainment, education, and e-commerce sectors in Japan.

It all starts with the threat actors exploiting the CVE-2024-4577 vulnerability to gain initial access and run PowerShell scripts to execute the Cobalt Strike reverse HTTP shellcode payload to grant themselves persistent remote access to the compromised endpoint.

The next step entails carrying out reconnaissance, privilege escalation, and lateral movement using tools like JuicyPotato, RottenPotato, SweetPotato, Fscan, and Seatbelt. Additional persistence is established via Windows Registry modifications, scheduled tasks, and bespoke services using the plugins of the Cobalt Strike kit called TaoWu.

“To maintain stealth, they erase event logs using wevtutil commands, removing traces of their actions from the Windows security, system, and application logs,” Raghuprasad noted. “Eventually, they execute Mimikatz commands to dump and exfiltrate passwords and NTLM hashes from memory on the victim’s machine.”

Cybersecurity

The attacks culminate with the hacking crew stealing passwords and NTLM hashes from the infected hosts. Further analysis of the command-and-control (C2) servers associated with the Cobalt Strike tool has revealed that the threat actor left the directory listings accessible over the internet, thereby exposing the full suite of adversarial tools and frameworks hosted on the Alibaba cloud servers.

PHP-CGI RCE Flaw Exploited

Notable among the tools are listed below –

  • Browser Exploitation Framework (BeEF), a publicly available pentesting software for executing commands within the browser context
  • Viper C2, a modular C2 framework that facilitates remote command execution and generation of Meterpreter reverse shell payloads
  • Blue-Lotus, a JavaScript webshell cross-site scripting (XSS) attack framework that enables the creation of JavaScript web shell payloads to conduct XSS attacks, capture screenshots, obtain reverse shell, steal browser cookies, and create new accounts in the Content Management System (CMS)

“We assess with moderate confidence that the attacker’s motive extends beyond just credential harvesting, based on our observation of other post-exploitation activities, such as establishing persistence, elevating to SYSTEM level privilege, and potential access to adversarial frameworks, indicating the likelihood of future attacks,” Raghuprasad said.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

About The Author

[email protected] The Hacker News

See author's posts

Original post here

What do you feel about this?

  • The Hacker News

Post navigation

Previous: Who is the DOGE and X Technician Branden Spikes?
Next: Safe{Wallet} Confirms North Korean TraderTraitor Hackers Stole $1.5 Billion in Bybit Heist

Author's Other Posts

Your Cloud Security Checklist Doesn’t Work the Way You Think It Does intruder.jpg

Your Cloud Security Checklist Doesn’t Work the Way You Think It Does

September 7, 2026 0 0
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts screen.jpg

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

September 7, 2026 0 0
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released tel.jpg

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

September 7, 2026 0 0
N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw nable.jpg

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

September 7, 2026 0 0

Related Stories

intruder.jpg
  • The Hacker News

Your Cloud Security Checklist Doesn’t Work the Way You Think It Does

[email protected] The Hacker News September 7, 2026 0 0
screen.jpg
  • The Hacker News

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

[email protected] The Hacker News September 7, 2026 0 0
tel.jpg
  • The Hacker News

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

[email protected] The Hacker News September 7, 2026 0 0
nable.jpg
  • The Hacker News

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

[email protected] The Hacker News September 7, 2026 0 0
chrome-cookies.jpg
  • The Hacker News

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

[email protected] The Hacker News September 7, 2026 0 0
micro.jpg
  • The Hacker News

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

[email protected] The Hacker News September 6, 2026 0 0

Trending Now

Your Cloud Security Checklist Doesn’t Work the Way You Think It Does intruder.jpg 1

Your Cloud Security Checklist Doesn’t Work the Way You Think It Does

September 7, 2026 0 0
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts screen.jpg 2

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

September 7, 2026 0 0
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released tel.jpg 3

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

September 7, 2026 0 0
N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw nable.jpg 4

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

September 7, 2026 0 0

Connect with Us

Social menu is not set. You need to create menu and assign it to Social Menu on Menu Settings.

Trending News

Your Cloud Security Checklist Doesn’t Work the Way You Think It Does intruder.jpg 1
  • The Hacker News

Your Cloud Security Checklist Doesn’t Work the Way You Think It Does

September 7, 2026 0 0
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts screen.jpg 2
  • The Hacker News

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

September 7, 2026 0 0
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released tel.jpg 3
  • The Hacker News

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

September 7, 2026 0 0
N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw nable.jpg 4
  • The Hacker News

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

September 7, 2026 0 0
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies chrome-cookies.jpg 5
  • The Hacker News

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

September 7, 2026 0 0
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication micro.jpg 6
  • The Hacker News

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

September 6, 2026 0 0
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner rev.jpg 7
  • The Hacker News

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

September 6, 2026 0 0

You may have missed

intruder.jpg
  • The Hacker News

Your Cloud Security Checklist Doesn’t Work the Way You Think It Does

[email protected] The Hacker News September 7, 2026 0 0
screen.jpg
  • The Hacker News

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

[email protected] The Hacker News September 7, 2026 0 0
tel.jpg
  • The Hacker News

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

[email protected] The Hacker News September 7, 2026 0 0
nable.jpg
  • The Hacker News

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

[email protected] The Hacker News September 7, 2026 0 0
Copyright © 2026 All rights reserved. | MoreNews by AF themes.