<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3acrushftpcrushftp/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 21 Sep 2026 19:13:25 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3acrushftpcrushftp/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CrushFTP Authentication Bypass Exploitation</title><link>https://feed.craftedsignal.io/briefs/2026-09-crushftp-auth-bypass/</link><pubDate>Mon, 21 Sep 2026 19:13:25 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-crushftp-auth-bypass/</guid><description>CVE-2025-31161 in CrushFTP is being exploited to gain unauthorized access and execute malicious commands, with activity linked to Hellcat ransomware operations.</description><content:encoded><![CDATA[<p>CVE-2025-31161 is a critical authentication bypass vulnerability in CrushFTP that allows unauthenticated remote attackers to gain unauthorized access to the application. Once the authentication mechanism is bypassed, attackers perform post-exploitation activities by executing system-level commands through the application's interface. Observed malicious activity includes the invocation of binaries like 'mesch.exe' or specific command arguments such as 'b64exec', 'fullinstall', or 'run'. This vulnerability has been actively exploited in the wild and linked to the Hellcat ransomware campaign. Defenders should monitor CrushFTP server logs for evidence of these specific command patterns, as they signify successful unauthorized access and subsequent execution of attacker-controlled code on the underlying host.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker sends a specially crafted HTTP request to the CrushFTP server to bypass authentication (CVE-2025-31161).</li>
<li>The application processes the request, allowing the attacker to reach restricted administrative or system-level endpoints.</li>
<li>Attacker uses the established session to execute arbitrary commands through the CrushFTP command interface.</li>
<li>Command execution triggers the launch of 'mesch.exe' or executes arguments like 'b64exec' or 'fullinstall'.</li>
<li>The server process spawns the requested commands, which may include further script execution or malware deployment.</li>
<li>Attacker gains persistence or performs reconnaissance on the system.</li>
<li>Attacker proceeds to stage and execute the final payload, such as Hellcat ransomware, for exfiltration and extortion.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows remote attackers to bypass authentication and execute code with the privileges of the CrushFTP service. This can lead to total system compromise, data theft, and the deployment of ransomware. The vulnerability has been explicitly linked to Hellcat ransomware campaigns, which target organizations using CrushFTP for file transfer services.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Patch CrushFTP immediately by upgrading to the version that remediates CVE-2025-31161.</li>
<li>Enable ingestion of CrushFTP logs into your SIEM and deploy the detection rules below to identify exploitation attempts.</li>
<li>Review all CrushFTP server activity for the command patterns 'mesch.exe', 'b64exec', 'fullinstall', or 'run' in process or execution logs.</li>
<li>Isolate internet-facing CrushFTP servers or apply strict access controls to limit exposure to these services.</li>
<li>Investigate any instances where unauthorized users or suspicious IPs are observed executing system commands via the CrushFTP interface.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>web</category><category>ransomware</category><category>vulnerability</category></item></channel></rss>