eSentire’s Threat Response Unit (TRU) has identified active exploitation of a six-year-old vulnerability, CVE-2019-18935, found in Progress Telerik UI for ASP.NET AJAX. This critical security flaw, which affects Internet Information Services (IIS) servers, allows attackers to execute remote commands and gain unauthorized access to targeted systems, posing a severe risk to environments that remain unpatched. Despite being discovered years ago, this vulnerability continues to be a significant attack vector, highlighting the ongoing challenge of addressing legacy security issues in enterprise systems. Attackers initiate their operations by scanning IIS servers for an active file upload handler. Once they locate a vulnerable endpoint, they use a customized proof-of-concept (PoC) exploit to upload a reverse shell—a .NET assembly that connects to a command-and-control (C2) server via Windows Sockets. After establishing access, attackers escalate their activities by executing reconnaissance commands, enumerating system users, and running tools such as cmd.exe within the IIS worker process (w3wp.exe). The reverse shell is often hidden in temporary directories with file names resembling random numerical patterns (e.g., 10-digit or 6-digit numbers followed by .dll). Attackers also employ the JuicyPotatoNG privilege escalation tool under deceptive file names like PingCaler.exe and JuicyPotatoNG.exe in public directories. Batch files such as rdp.bat and user.bat have been identified, although their exact functions remain uncertain. eSentire first observed these attacks in early January 2025 through anomalous activity logs on IIS servers, including exploitation attempts detected via requests to vulnerable Telerik Web UI endpoints such as WebResource.axd.
Another new threat group dubbed JINX 0164 has been observed targeting organizations associated with cryptocurrency operations through social engineering attacks carried out on Link...
Security researchers have uncovered a previously undocumented threat actor known as GREYVIBE, a Russian-linked cyber espionage group actively targeting Ukrainian military, governme...
Researchers have identified a ransomware campaign leveraging legitimate Windows scheduled tasks and system task execution mechanisms to evade security controls and execute maliciou...