logo

VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)

ID: b6a6ae81-b7ff-58ef-9c17-cef0914647c3

STIX ID: report--b6a6ae81-b7ff-58ef-9c17-cef0914647c3

Feed Name: Palo Alto Networks Unit 42

Threat Score
90/100

Date Published: 2026-02-19

Date Updated: 2026-04-28

Author: Justin Moore

...
...

Unit 42 reports active exploitation of CVE-2026-1731 — a critical (CVSS 9.9) pre-authentication RCE in BeyondTrust Remote Support's thin-scc-wrapper — enabling attackers to execute OS commands as the site user; observed post-exploitation activity includes account creation, webshell deployment, C2 traffic, backdoors (SparkRAT, VShell), lateral movement and data exfiltration across multiple sectors and countries, with hundreds to thousands of potentially exposed instances and detailed IoCs and mitigation guidance provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.