HomeSecurityLog4Shell: Still used for hacking into VMware servers

Log4Shell: Still used for hacking into VMware servers

According to a CISA warning , malicious actors including state-backed hacking groups continue to target VMware Horizon and Unified Access Gateway (UAG) servers by exploiting the Log4Shell remote code execution vulnerability (CVE-2021-44228).

See also: Amazon Web Services: Fixes container escape in Log4Shell hotfix

Log4Shell

Attackers can exploit Log4Shell remotely on vulnerable servers exposed to local or Internet access, to move laterally through networks until they gain access to internal systems containing sensitive data.

After its disclosure in December 2021, many malicious users began scanning and exploiting unpatched systems, including state-run hacking groups from China, Iran, North Korea, and Turkey.

Today, in a joint advisory with CGCYBER, the cybersecurity agency CISA said that servers have been compromised using Log4Shell exploits to gain initial access to targeted organizations' networks.

After breaching the networks, they deployed various malware strains, which gave them the remote access needed to deploy additional payloads and infiltrate hundreds of gigabytes of sensitive information.

“In one confirmed attack, these APT actors were able to move laterally within the network, gain access to a network, and collect and exfiltrate sensitive data.“

See also: Log4Shell exploits used for DDoS botnets and cryptominers installation

Organizations that have not yet patched their VMware servers are advised to mark them as hacked and initiate incident response (IR) procedures.

VMware

The steps required to properly respond to such a situation include immediately isolating potentially affected systems, collecting and reviewing relevant logs, engaging third-party IR experts (if necessary), and reporting the incident to CISA.

“CISA and CGCYBER recommend that all organizations with affected systems that have not promptly applied available patches or workarounds consider themselves affected and initiate threat response activities, using the IOCs provided in this Malware Analysis Report (MAR)-10382580-1 and MAR-10382254-1,” the two agencies said.

“If a potential breach, administrators should implement the incident response recommendations included in this CSA and report their key findings to CISA.“

See also: Black Basta ransomware: Linux version targets VMware ESXi servers

Since the beginning of the year, VMware Horizon servers have been targeted by Chinese malicious actors deploying the Night Sky ransomware, the Lazarus North Korean APT deploying information theft, and the Iran-linked TunnelVision hacking group deploying backdoors.

Until you can install fixes by updating all affected VMware Horizon and UAG servers to the latest versions, you can reduce the attack surface by “hosting key services in a DMZ,” deploying web application firewalls (WAFs), and “ensuring strict access controls around the network perimeter.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS