Active Exploitation
#threatreport #MediumCompleteness
CVE-2025-54068 Laravel Livewire Credential Theft Campaign: 6,000+ Applications Compromised | 23-06-2026
Source: https://www.imperva.com/blog/cve-2025-54068-laravel-livewire-credential-theft-campaign-6000-applications-compromised/
Key details below ↓
🎯Victims: E commerce, Healthcare, Financial services, Education, Government, Online gambling and betting, Logistics
🏭Industry: Government, Healthcare, E-commerce, Education, Logistic
🌐Geo: Asia, Indonesian, Asian, Brazilian
🔓CVEs: CVE-2025-54068 \[[Vulners](https://vulners.com/cve/CVE-2025-54068)]
- CVSS V3.1: *9.8*,
- Vulners: Exploitation: True
Soft:
- laravel livewire (<3.6.4)
📚TTPs:
⚔️Tactics: 4
🛠️Technics: 11
🧨IOCs:
- Url: 1
- File: 2
- Hash: 1
- IP: 1
- Domain: 1
- Email: 1
💽Software: Laravel Livewire, Livewire, Laravel, telegram, Unix, curl
🔢Algorithms: zip, sha256
📜Programming Languages: php
#threatreport:
On May 24, 2026, a major credential theft campaign exploiting CVE-2025-54068 was observed targeting Laravel Livewire applications, primarily affecting versions up to v3.6.3. This critical vulnerability arises from inadequate validation of component property updates during the hydration process, which allows unauthenticated attackers to inject malicious serialized PHP objects leading to arbitrary code execution upon deserialization. The attacker leveraged this flaw to execute a payload that fetched and executed a Bash script from their command-and-control (C2) server.
The captured payload indicated that the attacker used PHPGGC gadget chains, which exploit existing legitimate PHP classes within Laravel applications. The malicious Bash shell script, identified as shoc.enz, was a lightweight 5,269 bytes in size, and served as a credential stealer. Once executed, it set up a temporary working directory, ensured no other instances were running, searched for sensitive .env files containing crucial configuration data, archived these files, and subsequently exfiltrated them to multiple C2 channels, while also cleaning up to erase forensic traces.
Analysis revealed that over 6,167 applications across diverse sectors, including e-commerce, healthcare, financial services, and even governmental bodies, had their credentials compromised. The extant data included more than 1,850 database dumps and extensive email lists, indicating the active exploitation of stolen credentials. Indicators attributing the campaign to an Indonesian threat actor included linguistic elements in the malware’s code and metadata associated with the C2 infrastructure, including Telegram handles and an email address linked to multiple prior breaches in underground forums.
The targeted applications encompassed a wide array of Laravel deployments, including platforms related to online gambling, education, and logistics, thereby underscoring the indiscriminate nature of the scanning efforts. Any organization utilizing unpatched Laravel Livewire v3 versions was potential prey for this extensive campaign. Overall, the operation highlights significant vulnerabilities within widely used frameworks and the severe implications of their exploitation in the cyber realm.
Post summary
The report documents a large-scale credential theft campaign exploiting CVE-2025-54068, detailing the exploit chain and confirming active attacks against unpatched Laravel Livewire installations.