What happened
On October 8, 2026, the FBI, CISA, NSA and agencies from the UK, Australia, Canada, Japan, New Zealand and Spain published joint advisory AA26-281A on a scanning and exploitation platform called MicroScan. The advisory ties the activity to Integrity Technology Group and says it is "consistent with" groups tracked as Flax Typhoon, Ethereal Panda and RedJuliett. It has been observed "since at least mid-January 2021". The actors focus their scanning on a handful of ports, starting with port 21 (FTP). The advisory's table of successfully exploited CVEs includes CVE-2015-3306 in ProFTPD 1.3.5, marked as newly added to the KEV catalog. CISA added it the same day, together with four other older flaws, with a federal deadline of October 11.
The bug itself is from 2015. ProFTPD's bug 4169 describes it: mod_copy allowed its
SITE CPFR and SITE CPTO commands to be used by unauthenticated clients. Vadim
Melihow reported it, and ProFTPD fixed it in 1.3.5a, released May 27, 2015, and in
1.3.6rc1. NVD scores it CVSS 3.1 10.0. Exploit code has been public since April 2015.
A Metasploit module, "ProFTPD 1.3.5 Mod_Copy Command Execution," copies a PHP payload into the web
root (/var/www by default) and runs it.
Why it matters if you run public infrastructure
Nobody installs ProFTPD 1.3.5 today. These servers are the ones that never got touched again: an
old web host still offering FTP, a box set up for a file drop years ago, a forgotten appliance. That
is exactly what an automated platform scanning port 21 finds. The flaw needs no account. On a server
that also serves PHP from a known directory, copying a file into the web root is a straight path to
running code. The advisory lists the impact it observed as unauthorized read. Upstream does not
compile mod_copy by default, but Debian's packages load it in their stock configuration,
so many Linux installs have it switched on.
What to check this week
- Find every FTP service you expose, including on hosts you think of as web servers, and note the greeting each one sends on connect.
- Check the version with
proftpd -von the server. Upstream 1.3.5 is affected; 1.3.5a, 1.3.6rc1 and later are fixed. Distribution packages can carry the fix under the old number. Debian's fixed jessie package, for example, is 1.3.5-1.1+deb8u1, so check the package version too. - Check whether mod_copy is reachable. Connect without logging in and send
SITE CPFR /etc/passwd. A350reply means the server accepts the command from anonymous clients. The command only names a source file; it does not copy anything. - Upgrade, or turn mod_copy off. On a server that cannot be upgraded today,
comment out
LoadModule mod_copy.c(in Debian'smodules.conf) and restart. Better still, retire the server: the joint advisory's advice is to replace end-of-life products with supported ones. - Look for signs of compromise on any server that was exposed: unexpected
.phpfiles in the web root, andSITE CPFRorSITE CPTOcommands from unauthenticated sessions in the FTP logs. - Ask whether it needs FTP at all. Most of these services can be switched off or replaced with SFTP behind an allowlist.
How Attack Surface Scan covers this
Attack Surface Scan reads the greeting that FTP servers send on connect on hosts under your
verified domains, including hosts found through certificate transparency logs, and recognizes
ProFTPD. When the greeting includes the version, we match it against NVD's affected range (here,
exactly 1.3.5), and KEV-listed CVEs like this one rank first. A distribution package with the fix
backported still announces 1.3.5, so treat a match as "check this server," not proof. When the
version is hidden, we report the product but do not guess which CVEs apply. We do not send
SITE commands or exploit traffic. See Vulnerability
matching for the details.
Sources
- CISA, FBI, NSA et al.: Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data (AA26-281A)
- CISA: Known Exploited Vulnerabilities Catalog entry for CVE-2015-3306
- The Hacker News: FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails
- ProFTPD Bug 4169: Unauthenticated copying of files via SITE CPFR/CPTO allowed by mod_copy
- Debian: DSA 3263-1 proftpd-dfsg security update
- NVD: CVE-2015-3306 detail
- Rapid7: ProFTPD 1.3.5 Mod_Copy Command Execution (Metasploit module)