Since January 2025, an unidentified threat actor has been targeting organizations in Japan by exploiting CVE-2024-4577, a remote code execution (RCE) flaw in the PHP-CGI implementation on Windows, to gain initial access. Once inside, they execute PowerShell scripts to deploy a Cobalt Strike reverse HTTP shellcode payload, establishing persistent remote access. For post-exploitation, they leverage TaoWu, a set of publicly available Cobalt Strike plugins, enabling further control over compromised systems and facilitating lateral movement within the network.
