Open Nav
Sign Up

Buhti Ransomware

BUHTI Ransomware

Omer Pinsker

February 16, 2023

On Feb 15, 2023, the OP Innovate incident response team responded to multiple ransom attacks being carried out simultaneously on US companies. Some were perpetrated by a new group named “Buhti”.

The Buhti attack group is actively exploiting CVE-2022-47986 on IBM Aspera Faspex which allows a remote attacker to execute arbitrary code on the target system. This vulnerability is caused by a YAML deserialization flaw. Therefore by sending a specially-crafted obsolete API call, an attacker can exploit this vulnerability to execute arbitrary code on the system.

The vulnerability was discovered by an attack surface management tool (ASM) and reported to IBM in October 2022. In January 2023 IBM informed their customers about the vulnerabilities and released a patch. Cybersecurity companies around the world started publishing exploitation methods (including code examples) for this vulnerability and we assume that the ‘Buhti’ groups used these POCs to launch attacks against organizations around the world. 

We have also seen other reports of this vulnerability being exploited in the wild. There is not much information about the attack group but we assume that they are acting from the Balkan region since Buhti is a delicious Bulgarian dish.

The ransom demand:

Buhti Ransom note

According to OP Innovate’s threat intelligence, many attack groups around the world are discussing this vulnerability. According to our non-intrusive scans, more than 2000 companies located mostly in the United States and the United Kingdom are still exposed to Aspera Faspex vulnerabilities on their servers. 

How to remediate and mitigate:

  • Update Faspex to version 4.4.2 PL2.
  • Avoid externally exposing Faspex servers with versions that are lower than the patched version. 

More POCs will be shared in the future. 

For more information please contact us !

Resources highlights

Critical Zero-Day in CrushFTP Exploited in the Wild (CVE-2025-54309)

A critical zero-day vulnerability in CrushFTP, CVE-2025-54309, is being actively exploited by threat actors to gain unauthenticated administrative access to vulnerable servers via HTTPS. The…

Read more >

CVE-2025-54309

Critical Zero-Day in Microsoft SharePoint Actively Exploited (CVE-2025-53770)

A newly discovered zero-day vulnerability in Microsoft SharePoint Server, tracked as CVE-2025-53770, is currently being exploited in active attacks against on-premises environments. The flaw, rated…

Read more >

CVE-2025-53770

Over 600 Laravel Applications Vulnerable to Remote Code Execution via Leaked APP_KEYs (CVE-2018-15133, CVE-2024-55556)

Security researchers have uncovered a major RCE threat affecting over 600 Laravel applications, triggered by leaked APP_KEYs found on public GitHub repositories. Laravel's APP_KEY, typically…

Read more >

CVE-2018-15133, CVE-2024-55556

CVE-2025-3648: “Count(er) Strike” Vulnerability in ServiceNow

CVE-2025-3648, dubbed “Count(er) Strike”, is a high-severity vulnerability (CVSS 8.2) in ServiceNow's Now Platform, discovered by Varonis Threat Labs. The flaw allows both authenticated and…

Read more >

CVE-2025-3648

What to Look for in a Pentesting Platform (Beyond Just Scans)

Penetration testing platforms are a great way to centralize vulnerability discovery and triage. However, when evaluating penetration testing platforms, many organizations make the mistake of…

Read more >

pentesting platform

CVE-2016-10033: Actively Exploited Remote Code Execution (RCE) Vulnerability in PHPMailer

CVE-2016-10033 is a critical remote code execution vulnerability in PHPMailer, a widely used PHP library for sending emails. The flaw lies in the mailSend function…

Read more >

CVE-2016-10033
Under Cyber Attack?

Fill out the form and we will contact you immediately.