Threat Advisory

Chinese Hackers Exploit Zero-Day Vulnerability to Infect US ISPs with VersaMem Malware

Threat: Vulnerability/Malware
Threat Actor Name: Volt Typhoon
Threat Actor Type: State-Sponsored
Targeted Region: U.S.
Alias: Vanguard Panda, Bronze Silhouette, VOLTZITE
Threat Actor Region: China
Targeted Sector: Government & Defense, Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A zero-day vulnerability in Versa Director servers, identified as CVE-2024-39717, has been actively exploited in the wild. This vulnerability is present in Versa software-defined wide area network (SD-WAN) applications. Versa Director servers are crucial for managing network configurations for clients running SD-WAN software, making them a valuable target for threat actors. These servers, often used by internet service providers (ISPs) and managed service providers (MSPs), enable the orchestration of Versa's SD-WAN functionality, placing them at the core of enterprise network management.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A zero-day vulnerability in Versa Director servers, identified as CVE-2024-39717, has been actively exploited in the wild. This vulnerability is present in Versa software-defined wide area network (SD-WAN) applications. Versa Director servers are crucial for managing network configurations for clients running SD-WAN software, making them a valuable target for threat actors. These servers, often used by internet service providers (ISPs) and managed service providers (MSPs), enable the orchestration of Versa's SD-WAN functionality, placing them at the core of enterprise network management.[emaillocker id="1283"]

 

The exploitation of CVE-2024-39717 involves the deployment of a web shell named "VersaMem." This custom-tailored JAR web shell is designed to interact with Versa Director servers, primarily serving to intercept and harvest credentials, enabling unauthorized access to downstream networks. The web shell leverages the Java Instrumentation API and Javassist to dynamically modify Java code in memory, allowing the threat actors to avoid detection. It operates entirely in memory, loading additional Java modules without leaving traces on disk, making it particularly challenging to detect and mitigate. Initial access is gained through an exposed management port intended for high-availability (HA) pairing of Director nodes, leading to the deployment of VersaMem and subsequent exploitation of the affected systems.

 

In conclusion, the exploitation of this vulnerability poses significant risks to organizations relying on Versa Director servers, particularly those in the ISP, MSP, and IT sectors. The deployment of the VersaMem web shell allows threat actors to gain deep access to network configurations and potentially pivot into downstream networks. Given the severity of the vulnerability and the sophistication of the attack, it is crucial for affected entities to upgrade to the software version and implement the recommended mitigation steps to protect their systems from ongoing exploitation.

THREAT PROFILE:

Tactic Technique Id Technique
 Initial Access T1190 Exploit Public-Facing Application
Execution  T1059 Command and Scripting Interpreter
T1203 Exploitation for Client Execution
Defense Evasion T1078 Valid Accounts
T1027 Obfuscated Files or Information
Credential Access T1003 OS Credential Dumping
Command and Control  T1071 Application Layer Protocol
Impact T1486 Data Encrypted for Impact
 T1498 Network Denial of Service

RECOMMENDATION:

  • We strongly recommend you update Versa Director to version 22.1.4 or later.

REFERENCES:

The following reports contain further technical details:
https://arstechnica.com/security/2024/08/hackers-infect-isps-with-malware-that-steals-customers-credentials/

[/emaillocker]
crossmenu