Threat Advisory: VMware Horizon Servers Actively Being Hit With Cobalt Strike
ID: 6d9a5d34-8f46-5d77-bee7-a0fb0c365673
STIX ID: report--6d9a5d34-8f46-5d77-bee7-a0fb0c365673
Feed Name: Huntress Blog
Huntress confirms mass exploitation of Log4Shell (CVE-2021-44228 / CVE-2021-45046) against internet-facing VMware Horizon servers: their dataset found ~34% of sampled Horizon servers unpatched and ~10% backdoored with a modified absg-worker.js web shell, with exploitation activity observed Dec 25–29, 2021. A subsequent wave delivered Cobalt Strike via a PowerShell downloader (example callback to 185.112.83.116); the report provides detection tips (search for child_process strings, inspect process parentage such as ws_TomcatService.exe spawning PowerShell), mitigation steps (apply VMware patches, run Horizon mitigation tool, restore pre-compromise backups), and recommends incident response if a web shell is found.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
