Press ESC to close

Old Cisco ASA Vulnerability (CVE-2014-2120) Fuels Androxgh0st Botnet Activity

CategoryDetails
Threat ActorsAndroxgh0st botnet, leveraging Mozi botnet payloads.
Campaign OverviewExploitation of decade-old CVE-2014-2120 in Cisco ASA, alongside Atlassian JIRA and Sophos Firewall vulnerabilities.
Target Regions (Or Victims)Organizations using Cisco ASA, Atlassian JIRA, Sophos Firewall, Oracle EBS, and PHP frameworks globally.
MethodologyExploits CVE-2014-2120 for Cross-Site Scripting (XSS) and other vulnerabilities for RCE, persistence, and malware delivery.
Product TargetedCisco Adaptive Security Appliance (ASA), Atlassian JIRA, Sophos Firewall, PHP frameworks, Oracle EBS.
Malware ReferenceAndroxgh0st botnet, leveraging Mozi botnet.
Tools UsedBotnet payloads and appending methods for malware persistence.
Vulnerabilities ExploitedCVE-2014-2120 (Cisco ASA), CVE-2021-26086 (Atlassian JIRA), CVE-2021-41277 (Metabase GeoJSON API).
TTPsExploits XSS and RCE vulnerabilities; uses malware for persistence and lateral movement.
AttributionAndroxgh0st botnet operations observed since January 2024, incorporating IoT-focused tactics.
RecommendationsApply updates for affected systems (e.g., Cisco ASA, Atlassian JIRA), monitor attack surfaces, and leverage threat intelligence tools like SOCRadar.
SourceSocRadar

Read full article: https://socradar.io/cisco-asa-cve-2014-2120-fuels-androxgh0st-botnet/

Disclaimer: The above summary has been generated by an AI language model

Source: SOCRadar

Published on: December 4, 2024

Leave a Reply

Your email address will not be published. Required fields are marked *