Cybercrime gang exploited VeraCore zero-day vulnerabilities for years (CVE-2025-25181, CVE-2024-57968)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-57968 +1 in the same advisory: …25181 | Unrestricted File Upload in Advantive VeraCore upload.aspx Advantive VeraCore, a warehouse management and order fulfillment platform, contains an unrestricted file upload flaw (CWE-434) in its upload.aspx endpoint that fails to properly restrict what files can be uploaded and where they are stored. A remote attacker with no credentials can abuse the endpoint to write files into unintended, attacker-influenced folders on the server. By placing crafted files (for example, script files) into web-reachable directories, an attacker can typically escalate an arbitrary upload into webshell deployment and code execution on the hosting server. Any organization running VeraCore, especially instances with the upload endpoint reachable from the internet, is exposed. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-10, indicating active exploitation, and EPSS assigns a 32.3% probability of exploitation within 30 days (98th percentile). Do: Apply the mitigations required under CISA KEV/BOD 22-01, following Advantive's instructions, and contact the vendor for the fixed release since no patched version is specified in the available data. In the interim, restrict network access to upload.aspx (allow only trusted users or VPN/internal traffic), enforce file-type and destination validation at a WAF/reverse proxy where possible, and hunt for unexpected or recently modified files in VeraCore's web directories plus suspicious entries in web access logs to detect webshells or uploaded payloads. | 8.8 group max | 32% | KEV PoC ×2 |
| nicheroughly hundreds to low thousands of deployments (fulfillment/3PL and e-commerce operations running VeraCore) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | xegroups.com | d, establish reverse shells communicating with domains like xegroups[.]com,” the researchers noted . “In 2010, they developed AutoIT |
Full article583 words · extracted from helpnetsecurity.com · click to collapse
XE Group, a cybercriminal outfit that has been active for over a decade, has been quietly exploiting zero-day vulnerabilities (CVE-2025-25181, CVE-2024-57968) in VeraCore software, a popular solution for warehouse management and order fulfillment.

According to Intezer and Solis Security researchers, their targets are companies in the manufacturing and distribution sectors.
“In one instance, the group was found to have compromised an organization in 2020, maintaining persistent access to an endpoint for over four years,” Intezer researchers Nicole Fishbein, Joakim Kennedy and Justin Lentz shared.
Who is XE Group?
XE Group is believed to have Vietnamese origins. It’s known for exploiting known vulnerabilities in externally facing web services and platforms and using the achieved access to deploy credit card skimmers and password-stealing malware.
They have also been known for creating fake websites to trick users into revealing personal information, and selling stolen data on the dark web.
“The group utilizes customized ASPXSpy webshells, which provide unauthorized server access, with communication authenticated by unique base64-encoded strings such as ‘XeThanh|XeGroups.’ Obfuscation tactics include disguising executables as PNG files, which, when executed, establish reverse shells communicating with domains like xegroups[.]com,” the researchers noted.
“In 2010, they developed AutoIT scripts for automating email generation and validating stolen credit card data. By 2013, they had created the ‘Snipr’ credential-stuffing toolkit, targeting global point-of-sale systems.”
The most curious thing about these cyberattackers is their continuing use of the XE Group name and certain pseudonyms for domains, variable names, user agents, and various accounts (email, GitHub, social media), which means that they are apparently not overly concerned about concealing their identities or being tied to certain attack activities.
Exploitation of VeraCore zero-day vulnerabilities (CVE-2025-25181 CVE-2024-57968)
Researchers have discovered the compromise of one victim’s IIS server hosting VeraCore’s software in early November 2024, when post-exploitation activity originating from a webshell was detected.
“Upon investigating, Solis Security identified a few unique techniques the threat actor leveraged after gaining access to the system including: the exfiltration of web application config files, attempts to access remote systems, and attempts to execute a Remote Access Trojan (RAT) via obfuscated PowerShell commands to reflectively load shellcode into memory,” Intezer researchers shared.
A subsequent investigation dated the initial compromise of the server to January 2020, when they retrieved valid credentials by leveraging an SQL injection vulnerability (CVE-2025-25181) against the VeraCore application, and then used the credentials to authenticate to it and to exploit an upload validation vulnerability (CVE-2024-57968) within the app to upload a webshell.
The attackers “came back” in 2023, when they used a newer webshell to fetch configuration files from the web application and browse the application’s file directories. In November 2024, after uploading a newer ASPXSpy webshell variant to a different directory, they attempted to perform the actions identified by Solis Security. The webshell also allowed them to perform network and database reconnaissance and manipulation, and exfiltrate files and critical information.
“XE Group’s evolution from credit card skimming operations to exploiting zero-day vulnerabilities underscores their adaptability and growing sophistication. Their ability to maintain persistent access to systems, as seen with the reactivation of a webshell years after initial deployment, highlights the group’s commitment to long-term objectives,” Intezer researchers concluded.
The upload validation vulnerability (CVE-2024-57968) has been defanged in November 2024 by VeraCore maker Advantive, which temporarily disabled the vulnerable upload feature. There is currently no publicly available information regarding a patch for CVE-2025-25181.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/02/05/cybercrime-exploited-veracore-zero-day-vulnerabilities-cve-2025-25181-cve-2024-57968-xe-group/