A cyber attack leveraging Check Point’s patched CVE-2024-24919 vulnerability has targeted organizations across Europe, Africa, and the Americas. Security analysts have observed direct linkages to Chinese state-sponsored threat actors.
The intrusion chain, which deploys the ShadowPad backdoor and NailaoLocker ransomware, exploits unpatched VPN gateways to infiltrate critical infrastructure, primarily in manufacturing sectors.
The CVE-2024-24919 vulnerability (CVSS 8.6) allowed unauthenticated attackers to read arbitrary files on Check Point Security Gateways configured with IPSec VPN or Mobile Access blades.
Check Point’s telemetry revealed exploitation attempts beginning in April 2024, with threat actors using stolen credentials to authenticate via VPNs and masquerading as legitimate users.
Compromised endpoints often bore default hostnames like DESKTOP-O82ILGG, matching patterns observed in prior Chinese operations.
After establishing VPN access, attackers conducted network reconnaissance using RDP and SMB protocols, targeting domain controllers for privilege escalation.
The ShadowPad backdoor was deployed via DLL sideloading, abusing legitimate executables like AppLaunch.exe to load malicious libraries (e.g., mscoree.dll).
ShadowPad’s modular architecture, decrypted in memory using XOR-based algorithms, supported multiple command-and-control (C2) protocols, including HTTP(S) and UDP, with encrypted payloads.
This backdoor created persistence through Windows services and registry keys while exfiltrating system metadata like hostnames and private IPs.
In a subset of incidents, attackers deployed NailaoLocker ransomware via ShadowPad’s execution framework. The ransomware employed AES-256-CTR encryption with a .locked extension and dropped ransom notes in %ALLUSERPROFILE%.
Its core design included logging failed encryption attempts and a hardcoded mutex (Global\lockv7) to prevent re-infection.
Notably, NailaoLocker’s loader (NailaoLoader.dll) abused legitimate binaries like usysdiag.exe to sideload payloads, a tactic overlapping with Southeast Asian cybercrime groups.
Apply Check Point Security following updates:
This campaign underscores Chinese threat actors’ evolving hybrid tactics, blending cyber espionage with ransomware for operational flexibility.
The use of CVE-2024-24919 months after patching highlights systemic vulnerabilities in legacy VPN infrastructures, particularly in manufacturing sectors with delayed update cycles.
Check Point’s incident response team continues to collaborate with CERTs to disrupt C2 infrastructure, though the persistence of ShadowPad’s plugins suggests long-term risks require continuous vigilance.
Collect Threat Intelligence on the Latest Malware and Phishing Attacks with ANY.RUN TI Lookup -> Try for free
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…