HomeSecurityGeoServer: Critical vulnerability allows remote code execution

GeoServer: Critical vulnerability allows remote code execution

A stealthy malicious campaign emerged in early March 2025, exploiting a critical remote code execution vulnerability in GeoServer (CVE-2024-36401), to compromise publicly available geospatial servers.

GeoServer: Critical vulnerability

The attackers exploited JXPath query injection in Apache Commons libraries, allowing arbitrary code execution via specially crafted XML requests. This allowed them to silently deploy custom executables that leveraged legitimate passive-income software development kits (SDKs) and applications, effectively turning victims' networks into illegal proxy farms.

Palo Alto Networks: Research and analysis results

Within days of the initial wave of attacks, Palo Alto Networks observed a significant increase in detection activity against vulnerable GeoServer instances. Cortex Xpanse data revealed over 3,700 publicly accessible servers in the first week of May 2025 alone, highlighting the massive attack surface for threat actors.

See also: Apple zero-day: New vulnerability found – Update now

The monetization strategy behind this campaign focused on long-term silent operation rather than rapid resource consumption. Instead of deploying noisy cryptocurrency miners, the attackers delivered two main payloads: an SDK that silently aggregated bandwidth-sharing sessions on infected computers , and an application that created hidden directories and launched executables with a minimal resource footprint.

Both payloads mimicked legitimate passive-income services, making them difficult to detect through signature-based defenses. Victims remained unsuspecting as their computers silently forwarded web traffic or participated in residential proxy networks.

By embedding genuine Dart-compiled binaries, the attackers took advantage of cross-platform capabilities to target Linux servers and bypass detection signatures configured for more common malware languages. This shows that threat actors are investing in more professional malware engineering, moving beyond the narrow confines of classic attacks.

GeoServer: Critical vulnerability allows remote code execution

Indications of a breach included links to hxxp://37.187.74[.]75:8080 and hxxp://64.226.112[.]52:8080, where stage-one scripts, such as z593, were bringing in additional stagers.

See also: Russian Static Tundra exploits old Cisco vulnerability

GeoServer: Extensive vulnerability

One of the most insidious elements of this campaign is the exploitation of JXPath extension functions. Upon receiving a specially crafted GetPropertyValue request, GeoServer's property accessor mechanism would pass an expression, controlled by the attacker, to the iteratePointers method. This payload would then call the javax.lang.Runtime.exec function, causing remote command execution.

After successful execution, z593 acted as a stager, creating a hidden folder under /var/tmp/.cache and downloading two additional payloads: z401, which established the execution environment, and z402, which launched the main executable with an embedded SDK key.

By linking these stages, attackers ensured persistence, while also ensuring that bandwidth-sharing processes were automatically repeated across reboots. Through this meticulous, multi-layered approach, threat actors have shown how leveraging legitimate SDKs and file-sharing services can facilitate the monetization of network resources.

See also: Mozilla Firefox 142: Fix critical vulnerabilities

GeoServer: Critical vulnerability allows remote code execution

This monetization strategy allows the attacks to remain active for a long time, with users and organizations unaware that their infrastructure is being used for malicious activities. The stealthy nature of the campaign poses a particular challenge for security teams, who must act on three fronts. They must immediately implement GeoServer patches, monitor outbound connections to known addresses IP , and deploy behavioral analytics toolscapable of detecting strange JXPath queries to prevent similar campaigns.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The case demonstrates once again that threat actors are gradually moving from "noisy" exploits to low-profile, stealthy attacks aimed at continuous profitability, turning critical business infrastructure into sources of income.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS