VMware Horizon servers attacked by Iranian hackers with Log4j exploits
By MYBRANDBOOK
An Iranian-aligned hacking group tracked as TunnelVision was spotted exploiting Log4j on VMware Horizon servers to breach corporate networks in the Middle East and the United States.
The ultimate goal of TunnelVision appears to be the deployment of ransomware, so the group is not focused on cyber espionage only but data destruction and operational disturbance too. The name itself says that Tunneling is the process of routing data traffic in such a way that its transmission becomes obfuscated or even hidden.
TunnelVision dropped two custom reverse shell backdoors onto compromised machines. The first payload is a zip file that contains an executable named "InteropServices.exe," which contains an obfuscated reverse shell beaconing to "microsoft-updateserver[.]cf."
The second payload, which was predominately used by the threat actors in recent attacks, is a modified version of a one-liner PowerShell available on GitHub. The exploitation process involves the direct execution of PowerShell commands and the activation of reverse shells via the Tomcat service.
TunnelVision relies on this second backdoor to execute recon commands; create backdoor users and add them to the administrators' group; credential harvesting using Procdump, SAM hive dumps, and comsvcs MiniDump; download and execute tunneling tools, including Plink and Ngrok, used to tunnel RDP traffic; execution of a reverse shell utilizing VMware Horizon NodeJS component; perform RDP scans on the internal subnet using a publicly available port scan script.
Nazara and ONDC set to transform in-game monetization with ‘
Nazara Technologies has teamed up with the Open Network for Digital Comme...
Jio Platforms and NICSI to offer cloud services to government
In a collaborative initiative, the National Informatics Centre Services In...
BSNL awards ₹5,000 Cr Project to RVNL-Led Consortium
A syndicate led by Rail Vikas Nigam Limited (abbreviated as RVNL), along wi...
Pinterest tracks users without consent, alleges complaint
A recent complaint alleges that Pinterest, the popular image-sharing platf...
STERLITE TECHNOLOGIES LTD.
PRAMA HIKVISION INDIA PRIVATE LIMITED
TEJAS NETWORKS INDIA PVT. LTD.
GLOBUS INFOCOM LTD.
ICONS OF INDIA : SANTHOSH VISWANATHAN
Santhosh Viswanathan is the the Vice President and Managing Director f...
Icons Of India : RAJENDRA SINGH PAWAR
Rajendra Singh Pawar is the Executive Chairman and Co-Founder of NIIT ...
ICONS OF INDIA : RAJIV MEMANI
As Chair of the EY Global Emerging Markets Committee, Rajiv connects e...
C-DOT - Center of Development of Telematics
India’s premier research and development center focused on telecommu...
HPCL - Hindustan Petroleum Corporation Ltd.
HPCL is an integrated oil and gas company involved in refining, market...
NIC - National Informatics Centre
NIC serves as the primary IT solutions provider for the government of ...
Indian Tech Talent Excelling The Tech World - Aneel Bhusri, CEO, Workday
Aneel Bhusri, Co-Founder and Executive Chair at Workday, has been a le...
Indian Tech Talent Excelling The Tech World - ARVIND KRISHNA, CEO – IBM
Arvind Krishna, an Indian-American business executive, serves as the C...
Indian Tech Talent Excelling The Tech World - Vinod Dham, Founder & Executive Managing Partner, IndoUS Venture Partners
Vinod Dham, known as the “Father of the Pentium Chip,” has left an...