VMware Horizon servers attacked by Iranian hackers with Log4j exploits
By MYBRANDBOOK
An Iranian-aligned hacking group tracked as TunnelVision was spotted exploiting Log4j on VMware Horizon servers to breach corporate networks in the Middle East and the United States.
The ultimate goal of TunnelVision appears to be the deployment of ransomware, so the group is not focused on cyber espionage only but data destruction and operational disturbance too. The name itself says that Tunneling is the process of routing data traffic in such a way that its transmission becomes obfuscated or even hidden.
TunnelVision dropped two custom reverse shell backdoors onto compromised machines. The first payload is a zip file that contains an executable named "InteropServices.exe," which contains an obfuscated reverse shell beaconing to "microsoft-updateserver[.]cf."
The second payload, which was predominately used by the threat actors in recent attacks, is a modified version of a one-liner PowerShell available on GitHub. The exploitation process involves the direct execution of PowerShell commands and the activation of reverse shells via the Tomcat service.
TunnelVision relies on this second backdoor to execute recon commands; create backdoor users and add them to the administrators' group; credential harvesting using Procdump, SAM hive dumps, and comsvcs MiniDump; download and execute tunneling tools, including Plink and Ngrok, used to tunnel RDP traffic; execution of a reverse shell utilizing VMware Horizon NodeJS component; perform RDP scans on the internal subnet using a publicly available port scan script.
Nazara and ONDC set to transform in-game monetization with ‘
Nazara Technologies has teamed up with the Open Network for Digital Comme...
Jio Platforms and NICSI to offer cloud services to government
In a collaborative initiative, the National Informatics Centre Services In...
BSNL awards ₹5,000 Cr Project to RVNL-Led Consortium
A syndicate led by Rail Vikas Nigam Limited (abbreviated as RVNL), along wi...
Pinterest tracks users without consent, alleges complaint
A recent complaint alleges that Pinterest, the popular image-sharing platf...
ACER INDIA PVT. LTD.
DELL TECHNOLOGIES INDIA PVT. LTD.
TAC SECURITY SOLUTIONS
ADITYA INFOTECH LTD.
ICONS OF INDIA : SHAILENDER KUMAR
Shailender Kumar is senior vice president and regional managing direct...
ICONS OF INDIA : SANDIP PATEL
Sandip Patel is the Managing Director for IBM India & South Asia regio...
ICONS OF INDIA : RAJIV MEMANI
As Chair of the EY Global Emerging Markets Committee, Rajiv connects e...
C-DOT - Center of Development of Telematics
India’s premier research and development center focused on telecommu...
DRDO - Defence Research and Development Organisation
DRDO responsible for the development of technology for use by the mili...
HPCL - Hindustan Petroleum Corporation Ltd.
HPCL is an integrated oil and gas company involved in refining, market...
Indian Tech Talent Excelling The Tech World - Sundar Pichai, CEO- Alphabet Inc.
Sundar Pichai, the CEO of Google and its parent company Alphabet Inc.,...
Indian Tech Talent Excelling The Tech World - George Kurian, CEO, Netapp
George Kurian, the CEO of global data storage and management services ...
Indian Tech Talent Excelling The Tech World - REVATHI ADVAITHI, CEO- Flex
Revathi Advaithi, the CEO of Flex, is a dynamic leader driving growth ...