Threat actors exploited a critical remote code execution vulnerability (CVE-2024-36401) in the open-source GeoServer platform to breach a U.S. federal civilian executive branch agency. The attackers gained initial access to one GeoServer instance and, over a three-week period, used the same vulnerability to compromise a second GeoServer and move laterally to additional servers, including web and SQL servers. The attackers deployed web shells such as China Chopper, leveraged scripts for persistence and privilege escalation, and used living-off-the-land techniques to evade detection. The breach was detected after the agency's endpoint detection and response (EDR) tool flagged suspicious activity, prompting a CISA-led incident response. CISA noted deficiencies in the agency's response playbook, which allowed the attackers to maintain deeper access during the investigation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CISA disclosed that attackers had breached a U.S. federal civilian agency by exploiting the critical GeoServer vulnerability, warning organizations about the real-world impact of unpatched systems. Multiple outlets reported the same disclosure, but it reflects a single public reporting event.
Threat actors exploited the GeoServer vulnerability to compromise a U.S. federal civilian executive branch agency, according to later CISA reporting. The intrusion established this flaw as more than a theoretical risk and showed active exploitation against government targets.
A critical path traversal vulnerability in GeoServer, tracked as CVE-2024-36401, was publicly disclosed and fixes were made available. The flaw affected GeoTools/GeoServer installations and enabled remote code execution in some configurations.
3 references tracked. Mallory keeps watching after this page renders.
thecyberthrone.in
Open sourcesecurityaffairs.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.