KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike
Summary
A critical vulnerability in the KnowledgeDeliver LMS, a popular system in Japan, was exploited as a zero-day to deploy the Godzilla web shell. Attackers then used this access to deploy Cobalt Strike Beacon, indicating a sophisticated attack chain.
IFF Assessment
FOE
The exploitation of a zero-day vulnerability to deploy advanced tools like Cobalt Strike represents a significant threat to organizations using the affected LMS.
Severity
9.1
Critical
Defender Context
This incident highlights the importance of timely patching for popular software, especially in enterprise environments. Defenders should be vigilant for indicators of compromise related to Godzilla web shells and Cobalt Strike activity, particularly targeting organizations using LMS platforms.