Post-exploitation activity we found for *that* critical-severity CrushFTP flaw:
-MeshAgent installs ➡️ non admin users to local administrators groups
-AnyDesk RMM installs ➡️ credential harvesting
-Telegram bot malware 🤖
add a skeleton here at some point
6 months ago