← Back to Feed

MAR-10430311-1.v1 Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475

CVE-2022-47966CVE-2022-42475

September 6, 2023 · CISA Advisories · Severity: HIGH

This CISA Malware Analysis Report analyzes four files from an incident response engagement at an aeronautical sector organization. The files include two Meterpreter payload variants designed to establish interactive shells and two ASPX web shells for remote code execution. The report provides IOCs and YARA rules to help detect this activity linked to multiple nation-state threat actors.

Key Takeaways

  • CISA analyzed four files from an incident response at an aeronautical sector organization.
  • Two files are Meterpreter variants that connect to command and control servers for remote control.
  • Two ASPX web shells execute remote JavaScript code on the compromised victim server.
☕ Buy a Coffee