logo

Hackers Created Rogue VMs to Evade Detection in Recent MITRE Cyber Attack

ID: a699e026-fba6-5f5a-ae85-248897ab2f56

STIX ID: report--a699e026-fba6-5f5a-ae85-248897ab2f56

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-05-24

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

MITRE reports that the UNC5221 actor exploited two Ivanti Connect Secure zero-days in late December 2023 to bypass MFA, compromise vCenter, and create rogue VMs in a not-for-profit's NERVE environment; the intruder deployed a Golang backdoor (BRICKSTORM) and web shells (BEEFLUSH, BUSHWALK) to execute commands, tunnel SSH to ESXi, and maintain persistence. MITRE published detection guidance and PowerShell scripts (Invoke-HiddenVMQuery, VirtualGHOST) and recommended enabling secure boot to help detect and mitigate rogue VMs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.