SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Mass Exploitation Campaign Targeting Adobe ColdFusion Servers Detected During Christmas Holiday

Mass Exploitation Campaign Targeting Adobe ColdFusion Servers Detected During Christmas Holiday

A coordinated exploitation campaign targeted Adobe ColdFusion servers across the globe during the Christmas 2025 holiday period, generating 5,940 malicious requests that probed 10+ ColdFusion CVEs disclosed between 2023 and 2024. Telemetry indicates 68% of the activity occurred on December 25, sugge...

Jan 5, 2026By Padmashree P5 min read

A coordinated exploitation campaign targeted Adobe ColdFusion servers across the globe during the Christmas 2025 holiday period, generating 5,940 malicious requests that probed 10+ ColdFusion CVEs disclosed between 2023 and 2024. Telemetry indicates 68% of the activity occurred on December 25, suggesting deliberate timing to exploit reduced security monitoring during holidays. The vast majority of traffic (98%) originated from two IPs hosted by CTG Server Limited (Japan-based infrastructure), and the actor leveraged ProjectDiscovery Interactsh for out-of-band (OAST) callback verification, with JNDI/LDAP injection as the primary vector.

Background on the Threat Actor Behind the ColdFusion Christmas Campaign

A Single Coordinated Actor Using Japan-Based Infrastructure. Both SecurityAffairs and GreyNoise confirm that the mass exploitation of ColdFusion servers during Christmas 2025 was driven primarily by one threat actor, not multiple groups. This actor operated almost entirely from Japan-based infrastructure owned by CTG Server Limited, a hosting provider known for poor abuse management and previous associations with suspicious activity.

CVE VulnerabilityAffected versionsCVSS ScoreEPSS Score
CVE-2023-26359Arbitrary code execution 2018 Update 15, 2021 Update 5 and earlier.9.886.79%
CVE-2023-38205Access Control Bypass2018u18, 2021u8, 2023u2 and earlier.7.594.31%
CVE-2023-44353Remote Code Execution2023.5, 2021.11 and earlier.9.890.26%
CVE-2023-38203Remote Code Execution2018u17, 2021u7, 2023u1 and earlier.9.894.26%
CVE-2023-38204Remote Code Execution2018u18, 2021u8, 2023u2 and earlier.9.878.00%
CVE-2023-29298Access Control Bypass2018u16, 2021u6, 2023.0.0.330468 and earlier.7.894.29%
CVE-2023-29300Remote Code Execution2018u16, 2021u6, 2023.0.0.330468 and earlier.9.893.80%
CVE-2023-26347Access Control Bypass2023.5, 2021.11 and earlier.7.585.70%
CVE-2024-20767Arbitrary File Read2023.6, 2021.12 and earlier.7.494.15%
CVE-2023-44352Reflected XSS2023.5, 2021.11 and earlier.6.182.74%

Campaign Overview

  • Timeframe: December 2025, peak on Dec 25(68% of traffic).
  • Scale:5,940 ColdFusion-focused requests against 20 countries, United States (4,044 sessions), Spain (753), India (128) among top targets.
  • Attribution:Single actor using Japan-based CTG Server Limited infrastructure, two IPs accounted for 98% of observed activity.
  • Technique Validation:Interactsh (ProjectDiscovery) used to confirm exploitation via OAST callbacks; JNDI/LDAP injection often paired with WDDX deserialization to reach RCE conditions.
  • Automation Indicators: 1–5-second request intervals; concurrent operation of the two IPs; cycling through multiple attack types per target.

Primary Targets

  • ColdFusion servers operated by enterprises across North America, Europe, and Asia.
  • Public-facing ColdFusion deployments with outdated patches or exposed administrative paths.

Key Characteristics

  • Mass CVE exploitation: 10+ distinct ColdFusion vulnerabilities from 2023–2024 targeted in rapid succession.
  • Out-of-band verification: Extensive use of Interactsh to confirm callbacks from compromised hosts.
  • Deliberate holiday timing: Activity concentrated on Christmas Day, indicative of operational discipline and awareness of defender gaps.

Vulnerability Details

Tactics and Techniques (MITRE ATT&CK)

  • TA0001 – Initial Access: Exploit public-facing ColdFusion applications via JNDI/LDAP injection, deserialization RCE, and access control bypass.
  • TA0008 – Lateral Movement: Post-access expansion through ColdFusion administrator endpoints or dropped webshells.
  • TA0005 – Defense Evasion:OAST callbacks and minimal on-disk artifacts; template-driven scans to blend with background noise.

Indicators of Compromise (IOCs)

Primary Threat Actor Infrastructure (CTG Server Limited – AS152194):

  • 134.122.136[.]119
  • 134.122.136[.]96

Infection Method

Initial Access

Attackers scan for internet-exposed ColdFusion servers and send crafted HTTP requests that exercise deserialization (WDDX) or path/access bypass flaws on CFM/CFC endpoints, aiming for pre-auth code execution.

Exploitation

Primary vector is JNDI/LDAP injection chained through unsafe deserialization, commonly validated via Interactsh OAST callbacks to confirm vulnerable hosts in near real-time.

Payload Delivery

The actor relies on lightweight, callback-centric validation rather than bulky malware; webshells or in-memory execution may follow successful checks, reducing forensic artifacts.

Execution & Persistence

Post-exploitation involves admin endpoint access, webshell deployment, or further exploitation of N-day flaws to maintain access; the campaign’s cadence (1–5s) and multi-vector cycling indicate automated, persistence-focused operations.

Command-and-Control (C2)

C2 behavior primarily leverages OAST interactions and legitimate web interfaces, eschewing noisy beacons to evade traditional endpoint detection.

Impact

  • Pre-auth RCE & Access Bypass: Enables long-term unauthorized access, webshell deployment, and administrative manipulation of ColdFusion instances.
  • Service Risk: Chained exploits can degrade or disrupt critical web apps that rely on ColdFusion.
  • Broader Operation: ColdFusion exploitation represents 0.2% of a larger reconnaissance campaign that generated 2.5M+ requests across 767 CVEs and 47+ tech stacks, pointing to Initial Access Broker-style activity.

Visual Flow

Initial Access (pre-auth deserialization / access bypass) -> Exploitation (JNDI/LDAP + OAST callback verification) -> Post-Access (webshells / admin endpoints / file reads) -> Lateral Movement & Persistence (legitimate interfaces, low-noise ops)

Mitigation Steps

Patch & Harden Immediately: Update ColdFusion to the latest security updates.

Lock Down Admin & CFIDE Paths: Disable or restrict /CFIDE/administrator and related endpoints, enforce IP allow-listing and MFA, follow ColdFusion Lockdown Guide.

Detect OAST/JNDI Indicators: Monitor for Interactsh callback domains and JNDI/LDAP artifacts.

Threat Hunting & Response: Review logs for suspicious access to CFIDE/CFC endpoints, unexpected packet captures, and webshell indicators; respond with credential rotation and host isolation if compromise suspected.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

CVE Research

TA412/APT31: Mapping Threat Actor Patterns to CVE Exploitation Chains

A chronological look at how a long-running China-nexus espionage cluster evolved from server-side exploitation to a chained Chrome/Windows zero-day kit — and what that shift signals.

Sep 24, 2026

Open CVE-2026-94127: F5 BIG-IP APM Zero-Day Under Active Exploitation
CVE-2026-94127: F5 BIG-IP APM Zero-Day Under Active Exploitation

CVE Research

CVE-2026-94127: F5 BIG-IP APM Zero-Day Under Active Exploitation

Sep 24, 2026

Open No Account Needed: Critical WordPress Flaw (CVE-2026-87902) Lets Attackers Run Code on Some Servers — Patch Now
No Account Needed: Critical WordPress Flaw (CVE-2026-87902) Lets Attackers Run Code on Some Servers — Patch Now

CVE Research

No Account Needed: Critical WordPress Flaw (CVE-2026-87902) Lets Attackers Run Code on Some Servers — Patch Now

WordPress has fixed CVE-2026-87902, an unauthenticated path traversal in page-template resolution that can lead to remote code execution when theme and server conditions align. The issue affects WordPress from 4.7.0 through 7.1.1 and is patched in 7.1.2, with backports across older supported branches. This article covers how the flaw works, affected and fixed versions, impact, and recommended remediation.

Sep 23, 2026

Open Patch Analysis & Exploitation Timeline: Four CVEs, Two Confirmed Zero Days, CISA's September 8, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: Four CVEs, Two Confirmed Zero Days, CISA's September 8, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: Four CVEs, Two Confirmed Zero Days, CISA's September 8, 2026 KEV Additions

An analysis of four vulnerabilities added to the CISA Known Exploited Vulnerabilities catalog on September 8, 2026, covering public disclosure, patch availability, KEV inclusion, remediation deadlines, vulnerability classes, and patch prioritization considerations.

Sep 22, 2026