An unidentified threat actor compromised an internet-facing Adobe ColdFusion 9 server and deployed Cring ransomware across the victim’s network, according to Sophos. The attacker exploited CVE-2010-2861 to retrieve a password file and apparently used CVE-2009-3960 to upload a payload. Web shells and Cobalt Strike supported continued access and lateral movement, while credential theft, scheduled-task persistence and in-memory script execution helped the attacker obtain Domain Admin privileges and disable endpoint protection.
Approximately 79 hours after initial compromise, the attacker encrypted the server and virtual machine disk images, deleted Volume Shadow Copies and cleared event logs; several other machines were rendered unusable. Sophos recovered evidence from the partially recoverable server, which ran unsupported ColdFusion 9 and Windows Server 2008. The incident underscores the need to retire or isolate unsupported internet-facing systems, restrict administrative privileges and protect backups from deletion or encryption.

See which actors are running it and whether you're in range.
14 events from the most recent confirmed update back to the earliest known activity.
Sophos recovered logs and files from the partially recoverable ColdFusion server and reconstructed the attack by an unidentified threat actor. The investigation found that the internet-facing system ran an 11-year-old Adobe ColdFusion 9 installation on Windows Server 2008.
The attacker deleted Volume Shadow Copies, cleared Windows event logs, and re-enabled the Sophos security products previously disabled. The ransom note appeared as a message on the Windows login screen.
Approximately 79 hours after the initial breach, the attacker executed the ransomware payload msp.exe, encrypting the system and directories containing virtual machine disk images. Cring ransomware was also deployed on other machines in the victim's network, leaving several unusable.
After disabling protection, the attacker discovered a hypervisor and virtual machine disk files on the server. The attacker used PowerShell Get-VM and Stop-VM with the -TurnOff option to forcibly shut down the virtual machines.
Sophos blocked an attempt to load a Cobalt Strike beacon, after which the attacker used the web shell to disable Sophos endpoint protection and Windows Defender. Sophos Tamper Protection was not enabled on the compromised machine.
After another approximately four-hour pause, the attacker profiled the system, obtained Domain Admin privileges, and executed remote commands on other servers. Domain Admin credentials were used to spread Cobalt Strike beacons to additional machines.
The attacker created an account named agent$ with the password P@ssw0rd and granted it administrative permissions.
Approximately five hours later, the attacker used WMIC to invoke PowerShell and download 01.css and 02.css from an IP address geolocated to Belarus.
The attacker installed cfiut.cfm in the ColdFusion /CFIDE/ directory and used it to export the SAM, Security, and System registry hives, which can support credential harvesting. The exports were disguised as PNG files, downloaded from a publicly accessible web directory, and then deleted.
Approximately 62 hours after the initial compromise, the attacker returned through the beacon to upload files and execute commands. A scheduled task invoked wscript.exe with hexadecimal-encoded parameters, while a persistent loader retrieved, decrypted, and executed an additional script in memory.
The attacker wrote a base64-encoded web shell from csa.log to the ColdFusion web directory as cfa.css and used it to attempt to load a Cobalt Strike beacon. The beacon was subsequently used to overwrite the web shell with garbled data to hinder investigation.
The attacker apparently exploited ColdFusion's XML-handling vulnerability CVE-2009-3960 to upload a file through an HTTP POST request to /flex2gateway/amf. Investigators identified a web shell concealed inside a CSS file as a possible payload of this upload.
Approximately three minutes after scanning began, the attacker exploited ColdFusion's directory traversal vulnerability CVE-2010-2861 to retrieve password.properties.
An attacker using an IP address assigned to Ukrainian ISP Green Floid scanned more than 9,000 website paths in 76 seconds. The reconnaissance identified ColdFusion-specific administrative and login paths.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.