
Scripted CKEditor Exploitation Endpoints Surface Across Two Campaign Domains
Four newly documented URLs across kartacnictvi.cz and mokawafm.com expose the scripted initial-access mechanism behind a Lazarus Group CRAT implant campaign. Shared hex-timestamp query parameters reveal a productized exploitation template targeting vulnerable CKEditor-for-WordPress image upload and dialog endpoints.
Four newly documented URLs targeting the CKEditor-for-WordPress plugin across two domains — kartacnictvi.cz and mokawafm.com — now explicitly expose the scripted initial-access mechanism behind a campaign CTX Team has been tracking in connection with a Lazarus Group CRAT implant. Each URL follows the same path structure — wp-content/plugins/ckeditor-for-wordpress/ckeditor/plugins/image/ — and carries a hex-timestamp query parameter: ts=6A4310F7_1897026C, ts=6A431118_12AB12AC,…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read