Threats Feed
- Public
TunnelVision Threat Actor Exploits Log4Shell Vulnerability in VMware Horizon Servers
In early February 2022, the TunnelVision threat actor exploited a vulnerable VMware Horizon server using the Log4Shell vulnerability (CVE-2021-44228) to gain unauthorized access. The attack involved suspicious account creation, credential harvesting, and lateral movement using PSexec and RDP. The adversaries also harvested credentials using Procdump and downloaded Sysinternals and SSH tools. The intrusion was attributed to the Iranian-aligned TunnelVision activity cluster, based on observed TTPs and artifacts. The targeted sectors and countries are not specified in the report.
read more about TunnelVision Threat Actor Exploits Log4Shell Vulnerability in VMware Horizon Servers - Public
TunnelVision Exploits 1-Day Vulnerabilities to Unleash Ransomware
SentinelLabs tracks TunnelVision, an Iranian-aligned threat actor operating in the Middle East and the United States, characterized by wide exploitation of 1-day vulnerabilities and heavy reliance on tunneling tools. In early 2022, the group actively exploited the Log4Shell vulnerability (CVE-2021-44228) in VMware Horizon servers, spawning malicious processes via the Tomcat service to run PowerShell commands, deploy backdoors, create backdoor administrator accounts, harvest credentials via Procdump, SAM hive dumps, and comsvcs MiniDump, and perform lateral movement using Plink and Ngrok to tunnel RDP traffic. The group also previously exploited Fortinet FortiOS (CVE-2018-13379) and Microsoft Exchange ProxyShell (CVE-2021-34473). TunnelVision used a GitHub account ("protections20") to host payloads, and leveraged legitimate services including transfer.sh, pastebin.com, webhook.site, and ufile.io for C2 communication. A custom backdoor dropped as InteropServices.exe bears similarities to the PowerLess backdoor used by Phosphorus (Microsoft attribution), and the group has been linked to ransomware deployment — making it a potentially destructive actor beyond its espionage activities. SentinelLabs tracks this cluster separately from Phosphorus/Charming Kitten/Nemesis Kitten due to insufficient overlap data for a definitive merge.
read more about TunnelVision Exploits 1-Day Vulnerabilities to Unleash Ransomware