Affected Systems
Gogs version 10.0 (Git service) and n8n (workflow automation platform) - specific n8n versions not provided. Multiple attack vectors disclosed including signed driver abuse (Microsoft Defender BTR.sys), DLL sideloading via Grandoreiro, and ErrTraffic/Cruciferra BYOVD campaigns.
Exploitation Status
Active exploitation confirmed for Grandoreiro DLL sideloading (targeting Mexico, Spain, Peru, Argentina) and ErrTraffic/ClickFix campaigns. Gogs 10.0 and n8n RCE exploitation status not specified. Microsoft Defender BTR.sys abuse demonstrated in research (Check Point). No CVE identifiers published yet.
Business Impact
Organizations running Gogs 10.0 or n8n face remote code execution risk with severity rated high. Defender BTR.sys abuse enables EDR bypass via signed Microsoft driver, bypassing signature-based detection. DLL sideloading campaigns actively targeting Latin America with banking trojan Grandoreiro. ErrTraffic campaigns deliver multiple stealers (Remus, Vidar) via compromised WordPress sites. No CVSS scores or patch availability mentioned.
Urgency
🟠 Within 24 hours
Recommended Actions
- Identify and inventory all Gogs 10.0 and n8n instances in your environment; isolate or disable until patches are available
- Monitor for suspicious BTR.sys driver activity during boot-time, especially BTR_CLI tool usage mimicking Defender remediation processes
- Block or alert on DLL sideloading attempts involving Duplicate Files Finder (DFF) application and DCRCVDrv.sys driver loads
- Scan WordPress sites for ErrTraffic JavaScript loaders; monitor DNS queries to Polygon smart contracts used for C2 resolution
- Review endpoint logs for process termination of security tools and privilege escalation attempts via vulnerable signed drivers
