VORANT. Threat Intelligence Sign in Get the full feed

ColdFusion flaw exploited for webshells in Japan

high threat government-nationaltechnologyinfrastructure

Attackers exploited Adobe ColdFusion vulnerability CVE-2023-29300 to plant webshells on at least 66 devices in Japan, risking ORB-style relay abuse.

IPA (Japan's Information-technology Promotion Agency) reports that network-perimeter appliances running Adobe ColdFusion have been compromised via CVE-2023-29300, a remote code execution flaw already listed in CISA's Known Exploited Vulnerabilities catalog. Multiple domestic organizations had webshells installed on affected ColdFusion instances, and Taiwanese security vendor TeamT5 reported on March 18, 2024 that at least 66 devices in Japan were compromised through this vulnerability.

IPA warns that such network-penetrating attacks often lead to compromised devices being repurposed as Operational Relay Boxes (ORBs) — used to relay C2 traffic or obscure attacker origin, potentially turning victim organizations into unwitting stepping stones for further attacks against third parties. The advisory draws a parallel to the Volt Typhoon campaign in the US and Europe, which similarly abused vulnerable network devices (including TP-Link routers) for ORB-style relay infrastructure targeting critical infrastructure.

IPA urges organizations running Adobe ColdFusion to urgently apply patches per Adobe's APSB23-40 advisory (which also covers two additional vulnerabilities) and to review connection logs for signs of compromise or ORB-style relay activity, even if patches have already been applied. Organizations detecting evidence of exploitation are encouraged to report to IPA's contact point.

Mentioned in this report

Vulnerabilities CVE-2023-29300KEV
Threat actors Volt Typhoon
Malware Webshell
Campaigns Volt Typhoon

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/alert_orb.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free