From Credit Card Skimming to Exploiting Zero-Days
NetmanageIT OpenCTI - opencti.netmanageit.com

SUMMARY :
XE Group, a cybercriminal organization active since 2013, has evolved from credit card skimming to exploiting zero-day vulnerabilities. The group initially focused on web vulnerabilities and supply chain attacks but has now shifted to targeted information theft in manufacturing and distribution sectors. They have demonstrated increased sophistication by exploiting previously undocumented vulnerabilities in VeraCore software, including an SQL injection flaw and an upload validation vulnerability. XE Group maintains long-term access to compromised systems, as evidenced by their reactivation of a webshell planted years earlier. Their recent activities involve exfiltrating config files, network reconnaissance, and deploying a Remote Access Trojan using obfuscated PowerShell commands. The group's evolution highlights their adaptability and growing threat to supply chain security.
OPENCTI LABELS :
powershell,zero-day,meterpreter,aspxspy,webshell,supply-chain-attack,cve-2024-57968,information-theft,cve-2025-25181,remote-access-trojan,sql-injection,persistent-access
Open in NetmanageIT OpenCTI Public Instance with below link!
Use public read only username and password on login page.
NOTE : Use Public READ only user credentials on login page banner.
From Credit Card Skimming to Exploiting Zero-Days