A long-patched vulnerability in Magento and Adobe Commerce is being actively exploited in an attack chain that leads to the deployment of a persistent Linux backdoor. Dubbed StyleSmuggler, this operation represents a dangerous evolution from typical data skimming, granting attackers deep, lasting control over compromised servers and exposing critical patch management failures across the e-commerce ecosystem.

The attacks leveraged CVE-2022-24086, a severe remote code execution flaw patched by Adobe in February 2022. Despite the age of the patch, threat actors are successfully weaponizing the vulnerability to compromise unpatched systems. The exploit chain goes beyond initial web server access, allowing adversaries to install a stealthy backdoor on the underlying Linux infrastructure.

This marks a significant shift in attacker methodology. While Magecart-style campaigns typically focus on stealing payment card data at checkout, the StyleSmuggler approach establishes a resilient foothold. The installed Linux backdoor can persist through reboots and basic cleanup, providing attackers with long-term access. From this position, they can execute ransomware, move laterally across networks, exfiltrate data, or maintain a command-and-control presence.

The active exploitation of a flaw patched over four years ago underscores a systemic vulnerability management crisis. Adobe originally rated CVE-2022-24086 with a critical CVSS score of 9.8—a severity that remains fully relevant for any system still unpatched. The campaign is a stark reminder that known vulnerabilities are potent threats when maintenance lapses.

For IT administrators, immediate action is twofold. First, ensure all Magento instances are updated to the latest secure versions. Second, implement essential server hardening measures. This includes deploying file integrity monitoring to detect unauthorized changes, enforcing strict egress filtering to block suspicious outbound connections, and establishing continuous anomaly detection to identify suspicious processes or commands.

The StyleSmuggler campaign demonstrates that patching alone is insufficient. A modern defense requires a layered strategy that combines timely updates with rigorous infrastructure monitoring and security controls to protect against deep, system-level compromises.


Magento及Adobe Commerce中一個早已修補的漏洞正被積極利用於一個攻擊鏈中,導致部署持久性Linux後門。此行動被稱為StyleSmuggler,代表了相較於典型資料竊取手法的危險演變,賦予攻擊者對被入侵伺服器進行深入、長期的控制,並暴露出電子商務生態系統中嚴重的漏洞管理失敗。

攻擊者利用了CVE-2022-24086,這是一個Adobe於2022年2月修補的嚴重遠端程式碼執行漏洞。儘管補丁已發布一段時間,威脅行為者仍成功將此漏洞武器化,以入侵未修補的系統。此攻擊鏈超越了初始的網頁伺服器存取,允許攻擊者在底層Linux基礎架構中安裝隱蔽的後門。

這標誌著攻擊者方法論的重大轉變。典型的Magecart式攻擊活動通常側重於在結帳時竊取支付卡資料,而StyleSmuggler手法則建立了一個具韌性的立足點。已安裝的Linux後門可通過重啟和基本清理過程持續存在,為攻擊者提供長期存取權限。從此位置出發,他們可以執行勒索軟件、在網絡中橫向移動、滲出資料或維持命令與控制的存在。

對一個已修補超過四年的漏洞進行積極利用,凸顯了一場系統性的漏洞管理危機。Adobe最初為CVE-2022-24086評定的CVSS嚴重性評分為9.8——此嚴重程度對任何仍未修補的系統仍然完全適用。此攻擊活動是一個尖銳的提醒:當維護出現疏漏時,已知漏洞仍可能構成強大威脅。

對IT管理員而言,立即行動有兩方面。首先,確保所有Magento實例都更新至最新的安全版本。其次,實施必要的伺服器加固措施。這包括部署檔案完整性監控以偵測未經授權的變更、強制執行嚴格的出站過濾以阻止可疑的外部連線,以及建立持續的異常檢測以識別可疑的進程或命令。

StyleSmuggler攻擊活動表明,僅靠修補是不夠的。現代防禦需要一個分層策略,結合及時更新、嚴格的基礎架構監控和安全控制,以保護系統免受深入、系統層級的入侵。

新聞來源 / Original News Source