Threat Actors Weaponized SharePoint Flaw To Infiltrate Corporate Networks

Red | Attack Report
Download PDF

Threat Actors have leveraged SharePoint Remote Code Execution Flaw, CVE-2024-38094, to infiltrate corporate networks and deployed a Fast Reverse Proxy and a custom webshell to maintain control over the compromised systems. Their innovative tactic involves installing unauthorized security software that conflicted with and disabled existing security solutions, showcasing their evolving methods to circumvent traditional defenses.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox