TunnelVision
Named by SentinelOneSuspected state sponsor: Islamic Republic of IranTunnelVision is a threat tracking name used by SentinelOne for a Charming Kitten subgroup observed exploiting VPN vulnerabilities for initial access in early 2022. The group was documented rapidly exploiting critical flaws in Fortinet FortiOS, Pulse Connect Secure, and VMware Horizon to gain footholds in networks of interest in the Middle East and Europe. TunnelVision activity overlaps technically with the broader Charming Kitten and Mint Sandstorm cluster, sharing targeting patterns and post-exploitation tooling. The operations were noted for speed in weaponizing newly disclosed vulnerabilities, consistent with the technically mature subgroup described by Microsoft under the Mint Sandstorm name.
Targeted Regions
Middle EastMiddle East
Feb 2022 ~ Feb 2022
United StatesUnited States
Feb 2022 ~ Feb 2022
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.