Gbhackers Attackers Exploit WDigest Vulnerability to Harvest Plaintext Credentials
Article Content
- •Attackers exploited multiple vulnerabilities in Adobe ColdFusion to gain access.
- •Steganographic techniques were used to hide a webshell within an image file.
- •Windows credential protections were downgraded, allowing plaintext credential harvesting.
A multi-stage cyber attack targeted IIS servers, beginning with enumeration commands and escalating to credential extraction using Mimikatz. The attackers uploaded a steganographic webshell and executed a defense-impairment script (i.bat) that disabled logging and security services. Initial forensics indicated exploitation of Adobe ColdFusion vulnerabilities (CVE-2023-26360, CVE-2023-29298, CVE-2023-29300). The attackers employed steganography to conceal the webshell and manipulated Windows credential protections by enabling plaintext storage in memory. They also altered Microsoft Defender settings to disable monitoring, facilitating data exfiltration. The attack's scope included targeting Western and European environments, with the adversary returning to the compromised server after initial remediation efforts. The incident highlights significant risks associated with unpatched vulnerabilities and inadequate logging.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Ousaban and CVE-2023-26360 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…