BeyondTrust Flaw Sparks Global Web Shell Campaigns and Data Theft

1 min read
Source: The Hacker News
BeyondTrust Flaw Sparks Global Web Shell Campaigns and Data Theft
Photo: The Hacker News
TL;DR Summary

Threat actors are exploiting CVE-2026-1731 in BeyondTrust RS/PRA to run OS commands, deploy web shells and backdoors, establish C2, and exfiltrate data across sectors worldwide. Unit 42 reports use of a thin-scc-wrapper via WebSocket to execute commands in the site user context, effectively taking control of appliances and traffic. Campaigns include PHP backdoors, VShell, a bash dropper, and Spark RAT, with staged exfiltration of config files, internal databases, and PostgreSQL dumps. The activity aligns with prior CVE-2024-12356 issues, and CISA KEV confirms exploitation in ransomware operations.

Share this article

Reading Insights

Total Reads

1

Unique Readers

1

Time Saved

2 min

vs 3 min read

Condensed

80%

43986 words

Want the full story? Read the original article

Read on The Hacker News