Netskope Threat Labs

ET EXPLOIT [CORELIGHT] CrushFTP Auth Bypass Attempt (CVE-2025-31161)

IPS-NPA

1 SID: 2061619

Detects malicious activity associated with the [CORELIGHT] CrushFTP Auth Bypass malware family. The underlying exploit code targets CVE-2025-31161.