According to a CISA warning , malicious actors including state-backed hacking groups continue to target VMware Horizon and Unified Access Gateway (UAG) servers by exploiting the Log4Shell remote code execution vulnerability (CVE-2021-44228).
See also: Amazon Web Services: Fixes container escape in Log4Shell hotfix

Attackers can exploit Log4Shell remotely on vulnerable servers exposed to local or Internet access, to move laterally through networks until they gain access to internal systems containing sensitive data.
After its disclosure in December 2021, many malicious users began scanning and exploiting unpatched systems, including state-run hacking groups from China, Iran, North Korea, and Turkey.
Today, in a joint advisory with CGCYBER, the cybersecurity agency CISA said that servers have been compromised using Log4Shell exploits to gain initial access to targeted organizations' networks.
After breaching the networks, they deployed various malware strains, which gave them the remote access needed to deploy additional payloads and infiltrate hundreds of gigabytes of sensitive information.
“In one confirmed attack, these APT actors were able to move laterally within the network, gain access to a network, and collect and exfiltrate sensitive data.“
See also: Log4Shell exploits used for DDoS botnets and cryptominers installation
Organizations that have not yet patched their VMware servers are advised to mark them as hacked and initiate incident response (IR) procedures.

The steps required to properly respond to such a situation include immediately isolating potentially affected systems, collecting and reviewing relevant logs, engaging third-party IR experts (if necessary), and reporting the incident to CISA.
“CISA and CGCYBER recommend that all organizations with affected systems that have not promptly applied available patches or workarounds consider themselves affected and initiate threat response activities, using the IOCs provided in this Malware Analysis Report (MAR)-10382580-1 and MAR-10382254-1,” the two agencies said.
“If a potential breach, administrators should implement the incident response recommendations included in this CSA and report their key findings to CISA.“
See also: Black Basta ransomware: Linux version targets VMware ESXi servers
Since the beginning of the year, VMware Horizon servers have been targeted by Chinese malicious actors deploying the Night Sky ransomware, the Lazarus North Korean APT deploying information theft, and the Iran-linked TunnelVision hacking group deploying backdoors.
Until you can install fixes by updating all affected VMware Horizon and UAG servers to the latest versions, you can reduce the attack surface by “hosting key services in a DMZ,” deploying web application firewalls (WAFs), and “ensuring strict access controls around the network perimeter.”
