CNEXT is the name used in the provided content for CVE-2024-2961, a vulnerability in the iconv library of the GNU C Library (glibc). In the observed attacks, it was not described as a standalone malware family but as an exploit component chained with CosmicSting (CVE-2024-34102) against Adobe Commerce and Magento environments. Researchers reported that attackers used CosmicSting for arbitrary file read and theft of Magento secret encryption keys, then combined it with CNEXT to achieve remote code execution and full system compromise. Sansec stated that this chaining could allow attackers to take over the entire system. The activity was associated in particular with Group Belki, which used CosmicSting together with CNEXT to install backdoors and skimmer malware on compromised systems and establish persistent covert access. The broader campaign targeted e-commerce organizations running Adobe Commerce and Magento, with reported victim brands including Ray-Ban, National Geographic, Cisco, Whirlpool, and Segway. High-confidence indicators and identifiers directly mentioned in the content include CVE-2024-2961, its association with glibc iconv, and its use in August 2024 attack chains with CosmicSting to enable remote code execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attacks were orchestrated by seven different hacking groups exploiting the CosmicSting vulnerability (CVE-2024-34102) to inject malicious code and steal sensitive customer data... The vulnerability allowed attackers to steal secret cryptographic keys... With these keys, they generated API authorization tokens to embed payment skimmers on checkout pages. | Group Belki: This group utilizes the CosmicSting exploit in conjunction with CNEXT to install backdoors and skimmer malware on compromised systems.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Group Belki: This group utilizes the CosmicSting exploit in conjunction with CNEXT to install backdoors and skimmer malware on compromised systems.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A tool used alongside exploitation of CVE-2024-34102 (CosmicSting) to install backdoors on compromised Adobe Commerce/Magento systems, enabling persistent unauthorized access and facilitating follow-on payloads such as payment skimmers.
CNEXT is an exploit for a vulnerability (CVE-2024-2961) in the iconv library of glibc, which, when chained with CosmicSting, allows attackers to escalate to remote code execution on affected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.