// soc investigation 2026-05-18
SOC340 Apache Tomcat Serialized Payload RCE (CVE-2025-24813)
letsdefend critical ✓ true positive
mitre/T1190mitre/T1059mitre/T1083mitre/T1218-005mitre/T1041
analyst verdict TRUE POSITIVE
✓

🔍 What

CVE-2025-24813 exploitation confirmed against Apache Tomcat 9.0.90 on Tomcat-Server02. The attacker uploaded a serialized Java payload via partial PUT request to the Tomcat default servlet (letsattack.session), then triggered deserialization by repeatedly issuing GET requests to /hello-servlet. After iterating through multiple payload refinements (evidenced by sustained 500 errors), RCE was achieved. The attacker leveraged code execution to dump /etc/passwd and /etc/shadow to web-accessible staging files, which were then retrieved over HTTP. Machine has been contained.

🕐 When

May 30, 2025 — 18:18:42 to 18:24:18 UTC

🖥️ Where

👤 Who

💡 Why

Tomcat’s default servlet was configured with partial PUT enabled, allowing unauthenticated upload of arbitrary content directly to the webroot. The attacker exploited Java deserialization to execute OS-level commands and specifically targeted Linux credential stores. The repeated PUT/GET cycling with persistent 500 errors indicates iterative payload refinement — deserialization was firing but the payload required adjustment before commands executed cleanly.

📋 Attack Sequence

Time (UTC)RequestStatusNotes
18:18:42GET /bg-button.png200Initial recon / fingerprinting
18:19:29PUT /letsattack.session201First upload - file created in webroot
18:19:31GET /hello-servlet500Deserialization triggered, payload errors
18:19:47PUT /letsattack.session204Payload refined, re-uploaded
18:19:57PUT /check.txt204Webroot write-access verification
18:20:39GET /id.txt200RCE confirmed - id command output staged and retrieved
18:21:49GET /passwd.txt200/etc/passwd exfiltrated
18:23:25GET /shadow.txt404/etc/shadow attempt failed (file not yet staged)
18:24:18GET /shadow.txt200/etc/shadow exfiltrated

🎯 MITRE ATT&CK

Technique IDTacticTechnique
T1190Initial AccessExploit Public-Facing Application
T1059ExecutionCommand and Scripting Interpreter
T1083DiscoveryFile and Directory Discovery
T1005CollectionData from Local System
T1041ExfiltrationExfiltration Over C2 Channel

📌 IOCs

TypeValueDescription
IP3.15.143.228Attacker source IP
Fileletsattack.sessionMalicious serialized Java payload
Filecheck.txtWebroot write-access verification file
Fileid.txtStaged output of id command
Filepasswd.txtStaged copy of /etc/passwd
Fileshadow.txtStaged copy of /etc/shadow

🔬 Analysis Reports

🔗 AbuseIPDB (3.15.143.228) → https://www.abuseipdb.com/check/3.15.143.228 🔗 Akamai — Apache Tomcat CVE-2025-24813 Research → https://www.akamai.com/blog/security-research/march-apache-tomcat-path-equivalence-traffic-detections-mitigations