Skip to main content
Lazarus: ManageEngine RCE to QuiteRAT Espionage operation cover
COMING SOONIntermediate

Lazarus: ManageEngine RCE to QuiteRAT Espionage

An internet-facing ManageEngine ServiceDesk Plus appliance at Caldermoor Networks, a regional network and internet service provider, falls to the unauthenticated SAML RCE (CVE-2022-47966). Code runs as the appliance service account, which curls down a QuiteRAT first-stage implant, profiles the host and domain, installs itself as an auto-start Windows service, and beacons to a single HTTPS C2 that carries control and stolen data alike before pulling a CollectionRAT second stage. Work the ManageEngine web logs, the endpoint process tree, and the perimeter egress to reconstruct the intrusion. North-Korea-nexus actor.

55m
6 tasks
50 points
Free

Launches in 4 days

Aug 4, 2026

Tuesday, August 4, 2026 at 9:00 AM

Create your free account

Be ready the moment it drops, free.

Training Tools

SIEMXDRFirewall

What you'll investigate

6 objectives unlock when this operation goes live.

1Triage the appliance alert
2Find the entry point
3Recover the first-stage payload
4Expose the persistence
5Track the command channel
6Classify the persistence technique

Be first when it launches

Create your free account now. The moment this operation goes live on Aug 4, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.

Get Started Free