Hackers Created Rogue VMs to Evade Detection in Recent MITRE Cyber Attack
ID: a699e026-fba6-5f5a-ae85-248897ab2f56
STIX ID: report--a699e026-fba6-5f5a-ae85-248897ab2f56
Feed Name: The Hacker News
MITRE reports that the UNC5221 actor exploited two Ivanti Connect Secure zero-days in late December 2023 to bypass MFA, compromise vCenter, and create rogue VMs in a not-for-profit's NERVE environment; the intruder deployed a Golang backdoor (BRICKSTORM) and web shells (BEEFLUSH, BUSHWALK) to execute commands, tunnel SSH to ESXi, and maintain persistence. MITRE published detection guidance and PowerShell scripts (Invoke-HiddenVMQuery, VirtualGHOST) and recommended enabling secure boot to help detect and mitigate rogue VMs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
