Hackers Launch 2.5 Million+ Malicious Requests Targeting Adobe ColdFusion Servers
Security researchers have identified a large-scale coordinated exploitation campaign involving over 2.5 million malicious requests targeting vulnerable systems during the Christmas holiday period of 2025.
Security researchers have identified a large-scale coordinated exploitation campaign involving over 2.5 million malicious requests targeting vulnerable systems during the Christmas holiday period of 2025.
The campaign primarily focused on Adobe ColdFusion servers, with attackers also exploiting 46 additional technology stacks across nearly 800 vulnerabilities. Notably, the primary attack wave targeted over 10 Adobe ColdFusion CVEs, with close to 6,000 direct requests recorded against ColdFusion infrastructure.
Further analysis revealed that two primary IP addresses from the Japan-based hosting provider CTG Server Limited generated over 2.5 million requests across 767 distinct CVEs, using approximately 10,000 unique callback domains for attack verification.
The attackers timed the campaign to coincide with Christmas Day, concentrating 68% of the attack traffic during this period when security teams typically operate with reduced capacity. This timing suggests a highly organized threat actor with an understanding of enterprise security monitoring cycles.
Notably, the primary attack wave targeted over 10 Adobe ColdFusion CVEs, with close to 6,000 direct requests recorded against ColdFusion infrastructure.
The attackers utilized ProjectDiscovery Interactsh out-of-band callback infrastructure to verify successful exploitation attempts in real-time, allowing rapid identification of vulnerable systems for further compromise.
Critical vulnerabilities exploited include CVE-2023-26359, a deserialization RCE affecting ColdFusion, with 833 exploitation attempts, CVE-2023-38205, an access control bypass targeted 654 times, and CVE-2023-44353, which triggered 611 requests. The primary attack vector involved JNDI/LDAP injection through WDDX deserialization, using the JdbcRowSetImpl gadget chain for remote code execution.
Beyond ColdFusion, the campaign involved reconnaissance across various enterprise infrastructures. Researchers at Greynoise identified 4,118 unique HTTP fingerprints targeting Java application servers, web frameworks, CMS platforms, Atlassian products, network devices, and surveillance systems. The Confluence OGNL vulnerability CVE-2022-26134 alone received 12,481 requests, while the legacy Shellshock vulnerability CVE-2014-6271 triggered 8,527 attempts.
The threat actors operated from AS152194 (CTG Server Limited), a Hong Kong-registered hosting provider known for associations with phishing infrastructure and spam operations. The network is also identified as hosting FUNNULL CDN infrastructure targeting luxury brands, suggesting limited abuse enforcement mechanisms.
Organizations using Adobe ColdFusion servers should immediately apply security patches for CVE-2023-26359, CVE-2023-38205, and related vulnerabilities. Security teams are advised to implement network-based detection for JNDI injection payloads, OAST callback domains, and the identified threat actor IP addresses and JA4+ network fingerprints. Continuous vulnerability scanning and monitoring of exploitation attempt patterns remain essential defensive priorities.
Based on reporting by GBHackers.
