{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3acrushftpcrushftp/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2025-31161"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CrushFTP (\u003c 10.8.4)"],"_cs_severities":["high"],"_cs_tags":["web","ransomware","vulnerability"],"_cs_type":"threat","_cs_vendors":["CrushFTP"],"content_html":"\u003cp\u003eCVE-2025-31161 is a critical authentication bypass vulnerability in CrushFTP that allows unauthenticated remote attackers to gain unauthorized access to the application. Once the authentication mechanism is bypassed, attackers perform post-exploitation activities by executing system-level commands through the application's interface. Observed malicious activity includes the invocation of binaries like 'mesch.exe' or specific command arguments such as 'b64exec', 'fullinstall', or 'run'. This vulnerability has been actively exploited in the wild and linked to the Hellcat ransomware campaign. Defenders should monitor CrushFTP server logs for evidence of these specific command patterns, as they signify successful unauthorized access and subsequent execution of attacker-controlled code on the underlying host.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker sends a specially crafted HTTP request to the CrushFTP server to bypass authentication (CVE-2025-31161).\u003c/li\u003e\n\u003cli\u003eThe application processes the request, allowing the attacker to reach restricted administrative or system-level endpoints.\u003c/li\u003e\n\u003cli\u003eAttacker uses the established session to execute arbitrary commands through the CrushFTP command interface.\u003c/li\u003e\n\u003cli\u003eCommand execution triggers the launch of 'mesch.exe' or executes arguments like 'b64exec' or 'fullinstall'.\u003c/li\u003e\n\u003cli\u003eThe server process spawns the requested commands, which may include further script execution or malware deployment.\u003c/li\u003e\n\u003cli\u003eAttacker gains persistence or performs reconnaissance on the system.\u003c/li\u003e\n\u003cli\u003eAttacker proceeds to stage and execute the final payload, such as Hellcat ransomware, for exfiltration and extortion.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote attackers to bypass authentication and execute code with the privileges of the CrushFTP service. This can lead to total system compromise, data theft, and the deployment of ransomware. The vulnerability has been explicitly linked to Hellcat ransomware campaigns, which target organizations using CrushFTP for file transfer services.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch CrushFTP immediately by upgrading to the version that remediates CVE-2025-31161.\u003c/li\u003e\n\u003cli\u003eEnable ingestion of CrushFTP logs into your SIEM and deploy the detection rules below to identify exploitation attempts.\u003c/li\u003e\n\u003cli\u003eReview all CrushFTP server activity for the command patterns 'mesch.exe', 'b64exec', 'fullinstall', or 'run' in process or execution logs.\u003c/li\u003e\n\u003cli\u003eIsolate internet-facing CrushFTP servers or apply strict access controls to limit exposure to these services.\u003c/li\u003e\n\u003cli\u003eInvestigate any instances where unauthorized users or suspicious IPs are observed executing system commands via the CrushFTP interface.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-21T19:13:25Z","date_published":"2026-09-21T19:13:25Z","id":"https://feed.craftedsignal.io/briefs/2026-09-crushftp-auth-bypass/","summary":"CVE-2025-31161 in CrushFTP is being exploited to gain unauthorized access and execute malicious commands, with activity linked to Hellcat ransomware operations.","title":"CrushFTP Authentication Bypass Exploitation","url":"https://feed.craftedsignal.io/briefs/2026-09-crushftp-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}