![]() ![]() This does not imply we believe they are necessarily unrelated, only that there is at present insufficient data to treat them as identical to any of the aforementioned attributions.” concludes the report that also includes Indicators of Compromise (IoCs). “We track this cluster separately under the name “TunnelVision”. Vmware Vcenter, Vmware Vsphere, Vmware Workstation, Vmware View, Esxi, Aastra Ericsson Mx One. The researcher noticed that a dropped executable contains an obfuscated version of a reverse shell which is similar to PowerLess backdoor employed by the Iran-linked APT group APT35 (aka ‘ Charming Kitten‘, ‘ Phosphorus‘, Newscaster, and Ajax Security Team) in a recent wave of attacks.Įxperts also reported that the threat actor utilized a github repository “VmWareHorizon” associated with an account named “protections20” which is owned by the nation-state actor. ![]() The attackers used PowerShell commands to download tools like Ngrok and run further commands to establish reverse shells and drop a PowerShell backdoor used to gather credentials and perform lateral movements. The threat actors leverage the Log4Shell issue in VMware Horizon to run PowerShell commands, sending outputs back utilizing a webhook. “Typically, the threat actor initially exploits the Log4j vulnerability to run PowerShell commands directly, and then runs further commands by means of PS reverse shells, executed via the Tomcat process.” “TunnelVision attackers have been actively exploiting the vulnerability to run malicious PowerShell commands, deploy backdoors, create backdoor users, harvest credentials and perform lateral movement.” reads the analysis published by SentinelOne. In almost all the attacks, the threat actors deployed a tunneling tool, such as Fast Reverse Proxy Client (FRPC) and Plink, wrapped in a unique fashion. been deployed on VMware Horizon servers by the Chinese hacking group Deep. ![]() The TunnelVision group heavily leverages 1-day vulnerabilities in its campaigns.ĭuring the time SentinelOne experts monitored the activity of the group, the state-sponsored hackers exploited several flaws, including Fortinet FortiOS ( CVE-2018-13379), Microsoft Exchange ( ProxyShell) and recently Log4Shell. The guy in whose apartment they found the trolls server said he had no idea. TunnelVision’s TTPs overlap with the ones associated with Iran-linked nation-state actors Phosphorus, Charming Kitten and Nemesis Kitten. ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |