Since January 2025, an unidentified threat actor has been targeting organizations in Japan by exploiting CVE-2024-4577, a remote code execution (RCE) flaw in the PHP-CGI implementation on Windows, to gain initial access. Once inside, they execute PowerShell scripts to deploy a Cobalt Strike reverse HTTP shellcode payload, establishing persistent remote access. For post-exploitation, they leverage TaoWu, a set of publicly available Cobalt Strike plugins, enabling further control over compromised systems and facilitating lateral movement within the network.
Get through updates and upcoming events, and more directly in your inbox