← Back to Feed
MAR-10430311-1.v1 Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475
CVE-2022-47966CVE-2022-42475
September 6, 2023 · CISA Advisories · Severity: HIGH
This CISA Malware Analysis Report analyzes four files from an incident response engagement at an aeronautical sector organization. The files include two Meterpreter payload variants designed to establish interactive shells and two ASPX web shells for remote code execution. The report provides IOCs and YARA rules to help detect this activity linked to multiple nation-state threat actors.
Key Takeaways
- CISA analyzed four files from an incident response at an aeronautical sector organization.
- Two files are Meterpreter variants that connect to command and control servers for remote control.
- Two ASPX web shells execute remote JavaScript code on the compromised victim server.