Sunday, September 13, 2026

Over 200 Magento Stores Compromised In Rootkit Rampage via Zero-Day Exploit

A dangerous wave of attacks exploiting CVE-2025-54236, dubbed “SessionReaper,” in Magento e-commerce platforms.

This vulnerability lets attackers bypass authentication by reusing invalid session tokens, paving the way for session hijacking and full server takeovers.

Researchers uncovered multiple intrusion campaigns hitting Magento sites worldwide, with over 200 stores suffering root-level compromises.

In the most alarming incident, threat actors scanned and targeted 1,460 vulnerable Magento Commerce APIs.

Attackers listed these in a file called “success_api_2025.txt,” marking them for exploitation. From this pool, they fully breached 216 websites.

Each compromised site yielded files mimicking /etc/passwd listings, revealing user accounts and confirming root access. These leaks, shown in Oasis Security’s figures, prove attackers gained god-like control over servers.

The campaign relied on active command-and-control (C2) infrastructure at IP 93.152.230.161, hosted in Finland.

This setup orchestrated mass scans and exploits, turning vulnerable APIs into entry points. Oasis noted the aggressive scale: attackers didn’t just probe they methodically rooted systems, likely deploying rootkits for persistence.

Separate Webshell Attacks Hit Canada and Japan

Distinct operations targeted Magento sites in Canada and Japan, using the same CVE-2025-54236 flaw. Here, attackers uploaded web shells for ongoing access.

1,460 vulneralbe APIs, success_api_2025.txt (Source: oasis)

C2 traffic flowed through IP 115.42.60.163 in Hong Kong. Logs in files like “404_key.txt” and “key.txt” detail victim URLs, shell paths, and control keys.

Evidence from these logs shows successful uploads across multiple sites. For instance, structured entries list exact deployment paths, allowing remote code execution.

Figures from Oasis highlight Japan and Canada as hotspots, with shells placed at attacker-chosen locations on victim servers. This setup ensures persistent backdoors even after initial exploits.

216 victim sites identified (source:Oasis)
216 victim sites identified (source:Oasis)

Oasis stresses these incidents appear independent, involving different actors. Yet all exploit SessionReaper’s core weakness: poor session token invalidation in Magento.

Attackers capture tokens during legit sessions, replay them to impersonate admins, and escalate privileges.

CVE Details and Impact Table

CVE-2025-54236 affects Magento Commerce editions before patches. It scores high on CVSS due to its authentication bypass chain leading to RCE.

DetailInformation
CVE IDCVE-2025-54236 (SessionReaper)
Affected SoftwareMagento Commerce (unpatched)
Vulnerability TypeAuthentication Bypass, Session Hijacking
Exploitation ImpactRoot access, web shells, data theft
Victims Identified216 rooted sites + Canada/Japan webshells
C2 IPs93.152.230.161 (Finland), 115.42.60.163 (HK)

This table summarizes the flaw’s scope. Over 1,460 exposed APIs signal broader risk for unpatched stores.

Magento powers thousands of online shops, making it a prime target. SessionReaper joins a string of e-commerce vulns, like past POODLE-style flaws. Attackers favor it for stealth: no noisy brute-force, just token reuse.

Structured log entries listing victim URLs, deployed web shell paths, and control keys, key.txt(source:Oasis)
Structured log entries listing victim URLs, deployed web shell paths, and control keys, key.txt(source:Oasis)

Oasis discovered these via threat hunting, analyzing leaked files and logs. The /etc/passwd excerpts expose server internals, aiding lateral movement or ransomware prep.

In rooted sites, rootkits likely hide activities, stealing customer data or injecting malware.

Regions like North America, Europe, and Asia-Pacific report hits, with global scans amplifying spread.

Magento users must patch immediately. Adobe issued fixes; apply via composer updates. Scan for IOCs:

  • Monitor for C2 IPs: 93.152.230.161, 115.42.60.163.
  • Check logs for anomalous session reuse.
  • Harden sessions: enforce strict invalidation, token binding.
  • Use WAF rules blocking CVE-2025-54236 patterns.
  • Audit APIs; limit exposure.

This rampage underscores Magento’s patching urgency. With 200+ roots confirmed, unmitigated sites face imminent threats. Oasis urges vigilance as exploits evolve.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Related Articles

Recent News