APTMembers
APT

Scripted CKEditor Exploitation Endpoints Surface Across Two Campaign Domains

Four newly documented URLs across kartacnictvi.cz and mokawafm.com expose the scripted initial-access mechanism behind a Lazarus Group CRAT implant campaign. Shared hex-timestamp query parameters reveal a productized exploitation template targeting vulnerable CKEditor-for-WordPress image upload and dialog endpoints.

Jun 17, 2026, 13:31 (UTC+9)Last seenJun 30, 2026Severity100ByCTX TeamActorLazarus GroupHastati GroupIOC12MITRE19RegionsJO

Four newly documented URLs targeting the CKEditor-for-WordPress plugin across two domains — kartacnictvi.cz and mokawafm.com — now explicitly expose the scripted initial-access mechanism behind a campaign CTX Team has been tracking in connection with a Lazarus Group CRAT implant. Each URL follows the same path structure — wp-content/plugins/ckeditor-for-wordpress/ckeditor/plugins/image/ — and carries a hex-timestamp query parameter: ts=6A4310F7_1897026C, ts=6A431118_12AB12AC,…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence