Thứ Tư, Tháng Năm 18, 2022
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
No Result
View All Result
Home Tech

Initial access broker participates in Log4Shell attacks against VMware Horizon server

27 Tháng Một, 2022
in Tech
0
Initial access broker participates in Log4Shell attacks against VMware Horizon server
585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter

Các bài viết liên quan:

Download VSDC Video Editor Pro 7

Download VSDC Video Editor Pro 7

17 Tháng Năm, 2022
không gian bình yên giữa lòng Đồng Hới

không gian bình yên giữa lòng Đồng Hới

17 Tháng Năm, 2022
Russia may have withdrawn border defenses from Kharkiv

Russia may have withdrawn border defenses from Kharkiv

17 Tháng Năm, 2022
Information about the Kubet disc shock hack tool that players need to know

Information about the Kubet disc shock hack tool that players need to know

17 Tháng Năm, 2022
How to Screen Share on Google Duo on Android and the Web

How to Screen Share on Google Duo on Android and the Web

17 Tháng Năm, 2022
Beautiful dog pictures

Beautiful dog pictures

17 Tháng Năm, 2022

An access broker group originally tracked as Prophet Spider has been linked to a set of malicious activities that exploit the vulnerability. Log4Shell in the unpatched VMware Horizon Server.

According to new research published by BlackBerry’s Research & Intelligence and Incident Response (IR) team today, a cybercriminal attacker took the opportunity to weaponize the defect to download the second part onto the device. damaged systems.

The observed payloads included crypto miners, Cobalt Strike Beacons and web shells, corroborating previous advice from the UK’s National Health Service (NHS) that sounded the alarm. about actively exploiting vulnerabilities in VMware Horizon servers to remove malicious web shells and establish persistence on networks affected by subsequent attacks.

Log4Shell is a nickname used to refer to an exploit affecting the popular Apache Log4j library that resulted in the remote code execution by recording a specially crafted string. Since the vulnerability was made public last month, threat actors have been rapidly operating this new attack vector for a series of intrusion campaigns to gain full control of the affected servers.

BlackBerry says it has observed cases of tactics, techniques, and procedures that reflect exploits (TTPs) previously attributed to the Prophet Spider eCrime team, including the use of the “C: Windows Temp 7fde” to host malicious files and “wget .bin” executable to fetch additional binaries as well as overlaps in the infrastructure used by the team.

The Log4Shell Vulnerability

CrowdStrike noted in August 2021, when this group was found to be actively exploiting vulnerabilities in Oracle’s WebLogic servers to gain access to targeted environments.

Like many early access brokers, footholds are sold to the highest bidders on underground forums located in the dark web, who then exploit access to deploy ransomware. Prophet Spider is known to be active from at least May 2017.

This is not the first time that Internet-based systems running VMware Horizon have been attacked using the Log4Shell exploit. Earlier this month, Microsoft called a China-based operator tracked DEV-0401 to deploy a new strain of ransomware called NightSky on compromised servers.

The onslaught against Horizon servers also prompted VMware to urge its customers to apply patches immediately. The virtualization service provider warned: “The division of this vulnerability is very serious for any system, especially those that accept traffic from the open Internet.”

“When an access broker group is interested in a vulnerability of unknown scope, it is a good sign that attackers see significant value in exploiting it,” said Tony Lee, vice president. President of BlackBerry’s Worldwide Services Engineering Operations, said.

“It’s likely we’ll continue to see criminal groups explore Log4Shell vulnerabilities, so it’s an attack vector that defenders need to exercise constant vigilance on,” Lee added. .

.

.

Previous Post

Hồ Tràm Beach Boutique Resort & Spa – Review chi tiết từ A

Next Post

How to create a Livestream to play videos running continuously 24/7 like music

Admin Natuts

Admin Natuts

Related Posts

Information about the Kubet disc shock hack tool that players need to know

Information about the Kubet disc shock hack tool that players need to know

17 Tháng Năm, 2022
How to Screen Share on Google Duo on Android and the Web

How to Screen Share on Google Duo on Android and the Web

17 Tháng Năm, 2022
Beautiful dog pictures

Beautiful dog pictures

17 Tháng Năm, 2022
Coi chừng! Tin tặc bắt đầu khai thác lỗ hổng tường lửa Zyxel gần đây RCE

Coi chừng! Tin tặc bắt đầu khai thác lỗ hổng tường lửa Zyxel gần đây RCE

17 Tháng Năm, 2022
Use AI to turn sketches into real photos

Use AI to turn sketches into real photos

16 Tháng Năm, 2022
Volume buttons don’t work on iPhone [6 Proven Fixes]

Volume buttons don’t work on iPhone [6 Proven Fixes]

16 Tháng Năm, 2022
Load More
Next Post
How to create a Livestream to play videos running continuously 24/7 like music

How to create a Livestream to play videos running continuously 24/7 like music

Trả lời Hủy

Email của bạn sẽ không được hiển thị công khai. Các trường bắt buộc được đánh dấu *

Bài viết mới

Download VSDC Video Editor Pro 7
Software

Download VSDC Video Editor Pro 7

17 Tháng Năm, 2022
không gian bình yên giữa lòng Đồng Hới
Travel

không gian bình yên giữa lòng Đồng Hới

17 Tháng Năm, 2022
Russia may have withdrawn border defenses from Kharkiv
News

Russia may have withdrawn border defenses from Kharkiv

17 Tháng Năm, 2022
Information about the Kubet disc shock hack tool that players need to know
Tech

Information about the Kubet disc shock hack tool that players need to know

17 Tháng Năm, 2022
How to Screen Share on Google Duo on Android and the Web
Tech

How to Screen Share on Google Duo on Android and the Web

17 Tháng Năm, 2022
Beautiful dog pictures
Tech

Beautiful dog pictures

17 Tháng Năm, 2022
W3Schools

Ads

Contact: [email protected]

DMCA.com Protection Status

Categories

  • Android
  • Cạm bẫy tâm lí
  • Chưa được phân loại
  • Đồ họa
  • Đời sống
  • Gen Z
  • Health
  • iOS
  • Kĩ năng mềm
  • News
  • Nhà mạng
  • Phần mềm
  • Phần mềm đồ họa
  • Review sách
  • Software
  • Tech
  • Thiết kế ảnh
  • Thiết kế video
  • Thủ thuật
  • Travel
  • Văn hóa Nam Bộ
  • Văn học
  • Window

Browse by Tag

ai là triệu phú android Apple browser Bullet Journal bản thân Chỉnh ảnh data domain download du lịch fshare game game show hosting HÌNH XĂM IKEA ios khuyến mãi kinh doanh kiến thức kiểm tra pin lừa đảo messenger miễn phí mua sắm Máy ảnh mạng mồi tiềm thức network nghệ thuật nhà Trần quảng cáo review tháp phân tầng xã hội tiếng anh tiện ích Trần Thủ Độ tên miền từ vựng viettel word xã hội Đơn giản đánh bạc

Recent News

Download VSDC Video Editor Pro 7

Download VSDC Video Editor Pro 7

17 Tháng Năm, 2022
không gian bình yên giữa lòng Đồng Hới

không gian bình yên giữa lòng Đồng Hới

17 Tháng Năm, 2022

Trang tin nóng hổi - vừa thổi vừa xem

No Result
View All Result
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z

Trang tin nóng hổi - vừa thổi vừa xem