Attackers exploited Oracle WebLogic Server vulnerability CVE-2019-2725 to deploy the Sodinokibi ransomware, using the exposed AsyncResponderService endpoint to run commands on vulnerable servers. Cisco Talos reported in-the-wild activity beginning at least in mid-April, with exploitation intensifying after Oracle released an out-of-band patch for the flaw, which carried a CVSS 9.8 rating and could be abused by anyone with HTTP access to an unpatched WebLogic instance.
The intrusion chain used HTTP POST requests to launch cmd.exe and PowerShell, with some cases using certutil to fetch payloads such as radm.exe from attacker-controlled infrastructure. Once executed, Sodinokibi encrypted victim files and attempted to delete Windows shadow copies to obstruct recovery, while ransom instructions pointed victims to Tor-based payment resources and the clear-web domain decryptor[.]top. Talos also observed follow-on attempts to exploit the same WebLogic flaw to deliver GandCrab v5.2, indicating operators were opportunistically monetizing access to exposed enterprise servers.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
Roughly eight hours after deploying Sodinokibi, the attackers attempted another CVE-2019-2725 exploitation to distribute GandCrab v5.2. Talos assessed this as evidence of opportunistic monetization or uncertainty about whether the first ransomware deployment had succeeded.
Attackers sent HTTP POST requests to the AsyncResponderService endpoint on a vulnerable Oracle WebLogic server, executing cmd.exe and PowerShell or certutil to download and run payloads including radm.exe. The intrusion resulted in successful encryption on a number of systems and deletion attempts against Windows shadow copies.
Oracle released an out-of-band patch for the Oracle WebLogic Server vulnerability CVE-2019-2725. The flaw was described as easy to exploit by anyone with HTTP access to a vulnerable server.
Initial stages of the ransomware attack occurred as a trial to determine whether targeted Oracle WebLogic servers were exploitable. Talos described this as pre-deployment activity preceding the ransomware installation.
Cisco Incident Response and Cisco Talos observed attackers exploiting Oracle WebLogic vulnerability CVE-2019-2725 in the wild since at least this date. The activity later led to ransomware delivery against vulnerable servers.
The clear-web domain decryptor[.]top, later used to direct victims for payment and decryption instructions, was registered. Talos identified it as part of the Sodinokibi ransomware workflow.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.