Gbhackers Attackers Exploit WDigest Vulnerability to Harvest Plaintext Credentials
Article Content
- •Attackers exploited multiple vulnerabilities in Adobe ColdFusion to gain access.
- •Steganographic techniques were used to hide a webshell within an image file.
- •Windows credential protections were downgraded, allowing plaintext credential harvesting.
A multi-stage cyber attack targeted IIS servers, beginning with enumeration commands and escalating to credential extraction using Mimikatz. The attackers uploaded a steganographic webshell and executed a defense-impairment script (i.bat) that disabled logging and security services. Initial forensics indicated exploitation of Adobe ColdFusion vulnerabilities (CVE-2023-26360, CVE-2023-29298, CVE-2023-29300). The attackers employed steganography to conceal the webshell and manipulated Windows credential protections by enabling plaintext storage in memory. They also altered Microsoft Defender settings to disable monitoring, facilitating data exfiltration. The attack's scope included targeting Western and European environments, with the adversary returning to the compromised server after initial remediation efforts. The incident highlights significant risks associated with unpatched vulnerabilities and inadequate logging.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Ousaban and CVE-2023-26360 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Emergence of BraZetsu Malware: AI-Enhanced Threat from Exilware Group-IB has identified BraZetsu, a sophisticated Python-based Windows malware attributed to the Brazilian threat actor Exilware. This malware framework serves as a master toolkit for Initial Access Brokers (IABs), targeting compromised corporate systems primarily in Iberian and Latin American regions. Unlike…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…