ZeroHour
Security Affairspublished ()ingested @securityaffairs

XE Group shifts from credit card skimming to exploiting zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-9248
Cryptographic key leak (CWE-522) in Progress Telerik UI for ASP.NET AJAX & Sitefinity

Progress Telerik UI for ASP.NET AJAX (Telerik.Web.UI.dll) before R2 2017 SP1 and Progress Sitefinity before 10.0.6412.0 fail to adequately protect the Telerik.Web.UI.DialogParametersEncryptionKey and the ASP.NET MachineKey (CWE-522, insufficient key/credential protection). A remote, unauthenticated attacker can send crafted requests to the component's encrypted dialog-parameter handler to recover the dialog encryption key and then leak the MachineKey, and a public proof-of-concept exists (Exploit-DB 43873). With the MachineKey in hand, the attacker can forge or decrypt ASP.NET ViewState, upload or download arbitrary files, and inject XSS, which on IIS servers commonly chains to remote code execution via malicious ViewState. Any website or application embedding the vulnerable Telerik UI assembly, including older Sitefinity CMS releases, is affected. The flaw is confirmed exploited in the wild: it is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), carries a 75.1% EPSS score (99th percentile), and its use in ransomware campaigns is unknown.

Do: Upgrade Telerik UI for ASP.NET AJAX to R2 2017 SP1 or later and Sitefinity to 10.0.6412.0 or later per vendor instructions, as required by CISA's KEV listing. After patching, rotate the Telerik.Web.UI.DialogParametersEncryptionKey and the ASP.NET MachineKey, because keys leaked before patching remain usable to forge ViewState. Review IIS logs for requests to Telerik dialog handler endpoints and for unexpected file uploads, downloads, or ViewState-related anomalies.

9.875% KEV PoC
  • Progress (Telerik) UI for ASP.NET AJAX (Telerik.Web.UI.dll) all versions before R2 2017 SP1
  • Progress (Telerik) Sitefinity all versions before 10.0.6412.0
largetens of thousands of internet-exposed vulnerable installations (estimate)
CVE-2019-18935
Unauthenticated .NET Deserialization RCE in Progress Telerik UI for ASP.NET AJAX

CVE-2019-18935 is a .NET deserialization flaw (CWE-502) in the RadAsyncUpload function of Progress Telerik UI for ASP.NET AJAX through version 2019.3.1023. It is triggered when an attacker who knows the Telerik upload encryption keys — most commonly because the earlier flaws CVE-2017-11317 or CVE-2017-11357 exposed them, though keys can be obtained by other means — sends crafted serialized data to RadAsyncUpload, allowing remote code execution without authentication. Successful exploitation gives an attacker arbitrary code execution on the hosting IIS/ASP.NET web server, reflected in the critical 9.8 CVSS score. Any web application built with Telerik UI for ASP.NET AJAX at or below 2019.3.1023 is affected, unless 2019.3.1023 has the non-default hardening setting enabled (as of 2020.1.114 a default setting prevents the exploit). Exploitation is rampant in the wild: the flaw was added to CISA KEV on 2021-11-03 with known ransomware use, carries a 99.7% EPSS probability of exploitation, has multiple public exploits (Bishop Fox, RAU_crypto, noperator), and has been used by multiple threat groups — including ransomware and government-linked actors — to breach organizations including a U.S. federal agency.

Do: Upgrade to Progress Telerik UI for ASP.NET AJAX 2020.1.114 or later, where a default setting prevents exploitation (or, if staying on 2019.3.1023, enable the non-default hardening setting); per CISA KEV, apply updates per vendor instructions. Because exploitation requires the encryption keys to be known, also patch the older CVE-2017-11317/CVE-2017-11357 key-disclosure flaws or rotate the Telerik upload encryption keys. Check internet-facing IIS/ASP.NET applications for exposed RadAsyncUpload handlers and indicators of compromise, given known ransomware and federal-agency breaches.

9.8100% KEV ransomware PoC ×4
  • Telerik (Progress) UI for ASP.NET AJAX All versions through 2019.3.1023 (RadAsyncUpload exploitable when encryption keys are known; 2019.3.1023 requires a non-default setting to prevent exploitation;
largeTens of thousands of internet-exposed ASP.NET/IIS web applications using Telerik controls (order-of-magnitude estimate)
CVE-2024-57968
+1 in the same advisory: …25181
Unrestricted File Upload in Advantive VeraCore upload.aspx

Advantive VeraCore, a warehouse management and order fulfillment platform, contains an unrestricted file upload flaw (CWE-434) in its upload.aspx endpoint that fails to properly restrict what files can be uploaded and where they are stored. A remote attacker with no credentials can abuse the endpoint to write files into unintended, attacker-influenced folders on the server. By placing crafted files (for example, script files) into web-reachable directories, an attacker can typically escalate an arbitrary upload into webshell deployment and code execution on the hosting server. Any organization running VeraCore, especially instances with the upload endpoint reachable from the internet, is exposed. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-10, indicating active exploitation, and EPSS assigns a 32.3% probability of exploitation within 30 days (98th percentile).

Do: Apply the mitigations required under CISA KEV/BOD 22-01, following Advantive's instructions, and contact the vendor for the fixed release since no patched version is specified in the available data. In the interim, restrict network access to upload.aspx (allow only trusted users or VPN/internal traffic), enforce file-type and destination validation at a WAF/reverse proxy where possible, and hunt for unexpected or recently modified files in VeraCore's web directories plus suspicious entries in web access logs to detect webshells or uploaded payloads.

8.8
group max
32% KEV PoC ×2
  • Advantive VeraCore
nicheroughly hundreds to low thousands of deployments (fulfillment/3PL and e-commerce operations running VeraCore)
Full article461 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 10, 2025

The cybercrime group XE Group exploited a VeraCore zero-day to deploy reverse shells, web shells in recent attacks.

A recent investigation by researchers from Intezer and Solis Security shed light on the recent operations of the XE Group.

Active since at least 2013, XE Group is a cybercriminal group focused on credit card skimming and password theft via supply chain attacks.

“XE Group transitioned from credit card skimming to targeted information theft, marking a significant shift in their operational priorities.Their attacks now target supply chains in the manufacturing and distribution sectors, leveraging new vulnerabilities and advanced tactics.” reads the analysis published by Intezer.

“XE Group’s recent activities showcase their progression to exploiting zero-day vulnerabilities, signaling a strategic shift toward more advanced and impactful operations. This evolution reflects a commitment to adopting cutting-edge techniques and persistent attack strategies to achieve their objectives.”

The group was spotted using zero-day vulnerabilities in Advantive VeraCore respectively tracked as CVE-2024-57968 (CVSS score of 9.9) and CVE-2025-25181 (CVSS score of 5.8) to install reverse shells, web shells and maintain persistence.

The web shells employed in the attacks can explore the file system, exfiltrate and compress files, deploy a Meterpreter payload, perform network scanning, execute commands, and run SQL queries.

CVE-2024-57968 allows remote authenticated users to upload files to unintended folders, while CVE-2025-25181 is an SQL injection flaw enabling remote SQL execution (no patch available).

The group was also observed exploiting vulnerabilities in Telerik UI such as CVE-2017-9248 and CVE-2019-18935.

XE Group employs advanced tactics, including supply chain attacks with malicious JavaScript, custom ASPXSPY webshells, and obfuscated executables disguised as PNG files.

On November 5, 2024, Intezer spotted an attack attributed to XE Group, an EDR detected a post-exploitation activity through a webshell on an IIS server hosting VeraCore’s warehouse management system software.

The researchers found the threat actor exfiltrated config files, accessed remote systems, and used obfuscated PowerShell to run a RAT, but the good news is that EDR mitigated most actions.

“Their ability to maintain persistent access to systems, as seen with the reactivation of a webshell years after initial deployment, highlights the group’s commitment to long-term objectives.” concludes the report that also provides Indicators of Compromise (IoCs).

“By targeting supply chains in the manufacturing and distribution sectors, XE Group not only maximizes the impact of their operations but also demonstrates an acute understanding of systemic vulnerabilities. 
This blog has detailed the technical intricacies of their methods, offering valuable insights into their advanced tactics, the vulnerabilities they exploit (CVE-2024-57968, CVE-2025-25181), and the persistent nature of their attacks. Understanding these aspects is crucial for defenders aiming to stay ahead of this ever-evolving threat actor.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/174045/cyber-crime/xe-group-exploiting-zero-days.html