Researchers reported that XE Group, previously associated with credit card skimming, has been exploiting two zero-day flaws in Advantive VeraCore to gain and maintain access to vulnerable systems. The attack chain combines CVE-2025-25181, an unauthenticated SQL injection flaw in timeoutWarning.asp, with CVE-2024-57968, a critical authenticated path traversal and arbitrary file upload issue in /VeraCore/OMS/upload.aspx, allowing the group to compromise the application, upload ASPXSpy webshells, and establish persistent backdoor access.
The affected product includes VeraCore 2025.1.0 and earlier, and defenders were told that exploitation of CVE-2025-25181 may date back to 2020, indicating long-term abuse before public disclosure. Published reporting included webshell hashes and IP-based indicators tied to uploads, operator interaction, and XE Group command-and-control infrastructure. Advantive advised customers to upgrade to VeraCore 2024.4.2.1 or later to address CVE-2024-57968, while reporting indicated that no patch was yet available for CVE-2025-25181.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK published additional details on the two actively exploited VeraCore flaws, including affected versions, webshell hashes, and IP-based indicators linked to webshell uploads, operator interactions, and XE Group command-and-control activity. The report also stated that Advantive recommended upgrading to VeraCore 2024.4.2.1 or later for CVE-2024-57968, while no patch was yet available for CVE-2025-25181.
CSIRT.SK reported that exploitation of CVE-2025-25181 in Advantive VeraCore was first observed as early as 2020. The unauthenticated SQL injection flaw could lead to database compromise and broader application control.
Intezer and CSIRT.SK reported that XE Group was actively chaining two Advantive VeraCore vulnerabilities, CVE-2024-57968 and CVE-2025-25181, to upload ASPXSpy webshells and establish persistent access. The disclosures tied the activity to XE Group and included technical details on the attack chain and indicators of compromise.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.