Cleo’s trojan horse. [Research Saturday] episode artwork

EPISODE · Feb 8, 2025 · 18 MIN

Cleo’s trojan horse. [Research Saturday]

from CyberWire Daily · host N2K Networks

Mark Manglicmot, SVP of Security Services from Arctic Wolf, is sharing their research on "Cleopatra’s Shadow: A Mass Exploitation Campaign Deploying a Java Backdoor Through Zero-Day Exploitation of Cleo MFT Software." Arctic Wolf Labs discovered an ongoing exploitation campaign targeting Cleo Managed File Transfer (MFT) products, beginning on December 7, 2024. Threat actors used a malicious PowerShell stager to deploy a Java-based backdoor, dubbed Cleopatra, which features in-memory file storage and cross-platform compatibility across Windows and Linux. Despite Cleo's previous patch for CVE-2024-50623, attackers appear to have leveraged an alternative access method, exploiting the software's autorun feature to execute payloads and establish persistent access. The research can be found here: Cleopatra’s Shadow: A Mass Exploitation Campaign Deploying a Java Backdoor Through Zero-Day Exploitation of Cleo MFT Software

Episode metadata supplied by the publisher feed · Published Feb 8, 2025

Embed this episode

NOW PLAYING

Cleo’s trojan horse. [Research Saturday]

0:00 18:31

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of CyberWire Daily?

This episode is 18 minutes long.

When was this CyberWire Daily episode published?

This episode was published on February 8, 2025.

Can I download this CyberWire Daily episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!