{"id":9542,"date":"2025-12-30T10:03:39","date_gmt":"2025-12-30T10:03:39","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/30\/2-5-million-malicious-request-from-hackers-attacking-adobe-coldfusion-servers\/"},"modified":"2025-12-30T10:03:39","modified_gmt":"2025-12-30T10:03:39","slug":"2-5-million-malicious-request-from-hackers-attacking-adobe-coldfusion-servers","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/30\/2-5-million-malicious-request-from-hackers-attacking-adobe-coldfusion-servers\/","title":{"rendered":"2.5 Million+ Malicious Request From Hackers Attacking Adobe ColdFusion Servers"},"content":{"rendered":"<p>    2.5 Million+ Malicious Request From Hackers Attacking Adobe ColdFusion Servers<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A coordinated exploitation campaign that generated more than 2.5 million malicious requests against <a href=\"https:\/\/cybersecuritynews.com\/hackers-exploit-adobe-coldfusion-flaw\/\" target=\"_blank\" rel=\"noreferrer noopener\">Adobe ColdFusion<\/a> servers and 47+ other technology platforms during the Christmas 2025 holiday period.<\/p>\n<p>The operation was attributed to a single threat actor operating from Japan-based infrastructure. This indicates an advanced scanning effort by attackers seeking both legacy and new vulnerabilities dating back 20 years.<\/p>\n<p>The focused ColdFusion phase of the campaign exploited 10+ critical CVEs from 2023\u20132024, with peak activity on Christmas Day accounting for 68% of attack traffic.<\/p>\n<p>The deliberate timing during holiday downtime, when security teams typically operate at reduced capacity, suggests intentional targeting of monitoring gaps.<\/p>\n<p>Approximately 5,940 requests targeted ColdFusion servers across 20 countries, with the United States accounting for 68% of sessions.<\/p>\n<p>Two primary IP addresses (134.122.136.119 and 134.122.136.96) hosted by CTG Server Limited generated the vast majority of attack traffic.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj_c2rA3m488oZtrswJGKV6hBrXBn75R7xRjaliyqz99oaNFGCEveu6abaLv9mNNKC3wz6eQbfF1Gp9-hKnhZS-T-dcwsLUPyRCa5Rum_0CSZWxEZye3EhFCk9mo_gKvORXgesKh8z1spkL1nMMB46tt8hMVAOH0msp5-dECMSiYd35xWQmEw93h0nPR6ei\/w640-h554\/Heatmap.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Attack Heat map (Source: Greynoise)<\/figcaption><\/figure>\n<\/div>\n<p>The threat actor leveraged ProjectDiscovery Interactsh, an <a href=\"https:\/\/cybersecuritynews.com\/microsoft-msmq-bug-fixed\/\" target=\"_blank\" rel=\"noreferrer noopener\">out-of-band<\/a> testing platform, for callback verification, deploying nearly 10,000 unique OAST domains across oast.pro, oast. Site, and oast.me services.<\/p>\n<p>The primary attack vector exploited WDDX deserialization to trigger JNDI\/LDAP injection, targeting the com.sun.rowset.JdbcRowSetImpl gadget chain. Notably, the ColdFusion activity represents only 0.2% of the broader operation.<\/p>\n<p>Complete campaign analysis reveals systematic reconnaissance across 767 distinct CVEs affecting Java application servers, web frameworks, CMS platforms, and enterprise applications.<\/p>\n<p>The most frequently targeted vulnerabilities were <a href=\"https:\/\/cybersecuritynews.com\/csa-provides-common-vulnerability-exploited\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2022-26134<\/a> (Confluence OGNL injection) with 12,481 requests and <a href=\"https:\/\/cybersecuritynews.com\/251-malicious-ips-attacking-cloud-based-devices\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2014-6271<\/a> (Shellshock) with 8,527 requests.<\/p>\n<p>Network fingerprinting analysis identified 4,118 unique JA4H HTTP signatures, indicating that template-based scanning was likely performed using Nuclei or similar frameworks.<\/p>\n<p>The attacker\u2019s infrastructure <span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">exhibited concerning associations: CTG Server Limited previously hosted\u00a0<a href=\"https:\/\/cybersecuritynews.com\/operation-forumtrol-known-for-exploiting-chrome-0-day\/\" target=\"_blank\" rel=\"noopener\">phishing<\/a>\u00a0infrastructure targeting luxury brands, including Chanel and Cartier, and announced Bogon routes,<\/span> suggesting inadequate network hygiene.<\/p>\n<p>According to <a href=\"https:\/\/www.labs.greynoise.io\/grimoire\/2025-12-26-coldfusion\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">GreyNoise Labs,<\/a> organizations should immediately block the identified IP addresses and ASNs, implement signatures for the published JA4+ fingerprints, and prioritize patching ColdFusion and Java-based infrastructure.<\/p>\n<p>The campaign\u2019s scale and sophistication indicate advanced reconnaissance capabilities typical of initial access brokers preparing for downstream attacks.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/coldfusion-servers-under-attack\/\">2.5 Million+ Malicious Request From Hackers Attacking Adobe ColdFusion Servers<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/coldfusion-servers-under-attack\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>2.5 Million+ Malicious Request From Hackers Attacking Adobe ColdFusion Servers A coordinated exploitation campaign that generated more than 2.5 million malicious requests against Adobe ColdFusion servers and 47+ other technology platforms during the Christmas 2025 holiday period. The operation was attributed to a single threat actor operating from Japan-based infrastructure. This indicates an advanced scanning [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-9542","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9542"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9542"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9542\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9542"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9542"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9542"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}