
Active Exploitation of Check Point Zero-Day (CVE-2024-24919) Linked to Targeted APT Espionage Campaigns
State-sponsored actors are leveraging a critical vulnerability in Check Point gateways to gain initial access, bypass MFA, and infiltrate high-value government and corporate networks globally.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- High Confidence
- CVE:
- CVE-2024-24919
- Source:
- Mandiant
- Read Time:
- 5 min
Executive Summary
In the last 48 hours, Mandiant and Check Point Research have confirmed an alarming escalation in the exploitation of CVE-2024-24919, a critical information disclosure vulnerability affecting Check Point Security Gateways. This vulnerability, which was initially identified as a localized risk, has been weaponized by advanced persistent threat (APT) groups to facilitate large-scale cyber espionage. The campaign is characterized by its high degree of precision and its focus on bypassing traditional security perimeters to establish long-term persistence within diplomatic, defense, and critical infrastructure sectors.
Threat Analysis
CVE-2024-24919 resides in the way Check Point gateways handle certain requests to the Web Portals component when Remote Access VPN or Mobile Access is enabled. While categorized as 'information disclosure,' the practical impact is catastrophic. Attackers are using this vulnerability to retrieve sensitive system files, most notably the /etc/shadow file. In environments where local administrative accounts are used for emergency access or legacy management—often without the protection of multi-factor authentication (MFA)—this allows threat actors to crack password hashes and gain legitimate, authenticated access to the network core. Once authenticated, the actors pivot internally, often moving toward Active Directory (AD) servers or sensitive database environments to begin data exfiltration.
Technical Details
The exploitation involves a crafted HTTP POST request targeting the /clients/report endpoint. By utilizing directory traversal sequences, the attacker can read any file on the gateway's filesystem. Intelligence suggests that the primary threat actor, tracked as UNC5325, has integrated this exploit into an automated reconnaissance framework. Following the initial breach, the actor frequently deploys 'STREAK,' a memory-resident backdoor that hooks into the gateway's authentication process. This allows the attacker to intercept and log valid VPN session cookies, enabling continuous access even if the initial compromised credentials are changed. To further obscure their origins, the actors route their traffic through a complex network of compromised small office/home office (SOHO) routers, effectively blending in with legitimate residential traffic.
Attribution Assessment
Analysis of the TTPs, specifically the use of memory-only backdoors and the targeting of edge-device vulnerabilities, points toward a Chinese-nexus threat actor. There are significant technical overlaps with APT41 (Double Dragon) and the 'Volt Typhoon' cluster. The targeting profile is heavily skewed toward European diplomatic entities and Southeast Asian governmental bodies, aligning with known strategic intelligence requirements of the People's Republic of China. However, given the public disclosure of the exploit, other actors, including those associated with Russian intelligence (APT28), have also been observed attempting to capitalize on the vulnerability before widespread patching occurs.
Implications
The rapid weaponization of CVE-2024-24919 highlights a broader trend in the threat landscape: the systematic targeting of 'the edge.' As endpoint protection has improved, state-sponsored actors have pivoted toward security appliances that often lack internal visibility and third-party monitoring tools. This campaign demonstrates that even robust security architectures are vulnerable if the underlying edge infrastructure is compromised. The ability to bypass MFA through local account exploitation presents a significant challenge to Zero Trust implementations that do not account for gateway-level account risks.
Recommendations
Encrygma strongly recommends that all organizations operating Check Point Security Gateways apply the released hotfixes immediately. Furthermore, security teams should: 1) Disable local accounts for VPN access where possible, transitioning entirely to centralized, MFA-backed identity providers. 2) Conduct a comprehensive audit of all gateway logs for unauthorized access to sensitive file paths. 3) Monitor for anomalous internal lateral movement originating from gateway IP addresses. 4) Rotate all local passwords and secrets stored on the gateway devices if patching was delayed past May 24, 2024. Long-term strategies should include the implementation of micro-segmentation to limit the 'blast radius' of a compromised gateway.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
