ColdFusion Servers Under Attack
Executive Summary
A coordinated campaign targeted Adobe ColdFusion servers during the Christmas 2025 holiday, exploiting known vulnerabilities. The attackers aimed to gain initial access, likely for broader network reconnaissance.
Key TTPs
- Initial Access: Exploitation of vulnerabilities via HTTP POST commands.
- Execution: WDDX deserialization triggering JNDI injection to perform OAST validation.
- Defense Evasion: Exploiting predictable operational gaps during holidays.
Campaign Analysis
The attacks leveraged WDDX deserialization flaws to trigger JNDI and LDAP injection, targeting the
com.sun.rowset.JdbcRowSetImpl gadget chain. This technique has been used in Java ecosystems due to its reliability.Targeting & Infrastructure
- Target Profile: Adobe ColdFusion servers, particularly those in legacy enterprise environments.
- Infrastructure: Primarily from Japan-based infrastructure (CTG Server Limited).
Actionable Intelligence
- IPs:
134.122.136.119,134.122.136.96
Relevant Terms
- WDDX Deserialization: Exploitation of vulnerabilities in the Web Distributed Data Exchange (WDDX) format to execute malicious code.
- JNDI/LDAP Injection: Exploitation technique that leverages Java Naming and Directory Interface (JNDI) and Lightweight Directory Access Protocol (LDAP) to execute arbitrary code.
Source: SecurityWeek
