logo

Threat Advisory: VMware Horizon Servers Actively Being Hit With Cobalt Strike

ID: 6d9a5d34-8f46-5d77-bee7-a0fb0c365673

STIX ID: report--6d9a5d34-8f46-5d77-bee7-a0fb0c365673

Feed Name: Huntress Blog

Threat Score
80/100

Date Published: 2024-04-12

Date Updated: 2026-04-28

...
...

Huntress confirms mass exploitation of Log4Shell (CVE-2021-44228 / CVE-2021-45046) against internet-facing VMware Horizon servers: their dataset found ~34% of sampled Horizon servers unpatched and ~10% backdoored with a modified absg-worker.js web shell, with exploitation activity observed Dec 25–29, 2021. A subsequent wave delivered Cobalt Strike via a PowerShell downloader (example callback to 185.112.83.116); the report provides detection tips (search for child_process strings, inspect process parentage such as ws_TomcatService.exe spawning PowerShell), mitigation steps (apply VMware patches, run Horizon mitigation tool, restore pre-compromise backups), and recommends incident response if a web shell is found.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.