Attackers compromised an internet-facing Adobe ColdFusion 9 server on Windows Server 2008 and deployed Cring ransomware after exploiting the long-known vulnerabilities CVE-2010-2861 and CVE-2009-3960. The intrusion began with retrieval of sensitive files and upload of a web shell, then expanded into persistence, credential theft, and lateral movement as the operators worked toward Domain Admin privileges. Sophos said the attackers also used additional web shells, Cobalt Strike, scheduled tasks, WMIC, and PowerShell during the intrusion.
The operators attempted to evade detection by deleting logs, overwriting artifacts, and disabling Sophos endpoint protection and Windows Defender. They stole registry hives, created an administrative account, shut down hosted virtual machines, deleted Volume Shadow Copies, and encrypted both the compromised server and VM disk files roughly 79 hours after the initial breach. The case underscores the exposure created by leaving public-facing, end-of-life systems unpatched, as both ColdFusion 9 and Windows Server 2008 were unsupported at the time of the attack.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
Windows Server 2008 reached end of life in January 2020. Sophos said this meant the victim could not patch the operating system during the intrusion.
Adobe ColdFusion 9 was no longer supported as of 2016. Sophos noted this left the victim unable to patch the ColdFusion software at the time of the attack.
About 79 hours after the initial breach, the attackers executed a ransomware binary named msp.exe. It encrypted the compromised server and folders containing virtual machine disk images.
After discovering the compromised server hosted a hypervisor, the attackers executed a PowerShell command to stop and power off virtual machines.
When some activity was blocked, the attackers used the web shell to disable Sophos endpoint protection and Windows Defender. Sophos noted Tamper Protection was not enabled on the compromised machine.
The intruders created a local administrative user named agent$ with password P@ssw0rd, profiled the environment, obtained Domain Admin privileges, and executed remote commands on other servers. They also dropped Cobalt Strike beacons onto additional machines in the victim network.
About five hours after stealing the registry hives, the attackers used WMIC to invoke PowerShell and download files named 01.css and 02.css from an IP address geolocating to Belarus.
The attackers placed a second web shell, cfiut.cfm, in the ColdFusion /CFIDE/ directory and used it to export the HKLM\SAM, HKLM\Security, and HKLM\System registry hives. They saved the hives with .png extensions in a public web path, downloaded them, and deleted them.
Roughly 62 hours after the initial compromise, the attackers returned and used the beacon to upload files and execute commands. They dropped files into ProgramData and created a scheduled task using wscript.exe with hexadecimal-encoded parameters for persistence.
Using the web shell, the attackers attempted to load a Cobalt Strike beacon onto the server. They later overwrote the web shell file with garbled data to hinder forensic investigation.
The intruders exploited CVE-2010-2861 to retrieve password.properties and then abused CVE-2009-3960 via /flex2gateway/amf to upload a web shell. Sophos recovered the shell from a CSS file in the ColdFusion webroot.
The attacker scanned the target website from an IP address assigned to Ukrainian ISP Green Floid, requesting more than 9,000 paths in 76 seconds. The scan identified ColdFusion-specific paths including /admin.cfm, /login.cfm, and /CFIDE/Administrator/.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.