Tag: MITRE Corporation

Hackers Created Rogue VMs to Evade Detection in Recent MITRE Cyber Attack
News

Hackers Created Rogue VMs to Evade Detection in Recent MITRE Cyber Attack

According to information released by the MITRE Corporation, the threat actor in the cyberattack that targeted the non-profit organization in late December 2023 used rogue virtual machines (VMs) in its VMware environment to take advantage of zero-day vulnerabilities in Ivanti Connect Secure (ICS). According to MITRE researchers Lex Crumpton and Charles Clancy, the adversary used hacked vCenter Server access to establish their own rogue virtual machines (VMs) inside the VMware environment. They developed and implemented BEEFLUSH, a JSP web shell, under the Tomcat server of vCenter Server to run a Python-based tunneling tool, enabling SSH connections between VMs produced by adversaries and the ESXi hypervisor infrastructure. By hiding their malicious activity from centralized manage...