ATT&CKReferencesLumen Versa 2024

Lumen Versa 2024

Black Lotus Labs. (2024, August 27). Taking The Crossroads: The Versa Director Zero-Day Exploitaiton. Retrieved August 27, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns1

Procedure examples16

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareVersaMem

VersaMem encrypted captured credentials with AES then Base64 encoded them before writing to local storage.

T1040
Network Sniffing
MalwareVersaMem

VersaMem hooked the Catalina application filter chain `doFilter` on compromised systems to monitor all inbound requests to the local Tomcat web server, inspecting them for parameters like passwords and follow-on Java modules.

T1056
Input Capture
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation intercepted and harvested credentials from user logins to compromised devices.

T1056.004
Credential API Hooking
MalwareVersaMem

VersaMem hooked and overrided Versa's built-in authentication method, `setUserPassword`, to intercept plaintext credentials when submitted to the server.

T1059
Command and Scripting Interpreter
MalwareVersaMem

VersaMem was delivered as a Java Archive (JAR) that runs by attaching itself to the Apache Tomcat Java servlet and web server.

T1070.004
File Deletion
MalwareVersaMem

VersaMem deleted files related to initial installation such as temporary files related to the PID of the main web process.

T1071.001
Web Protocols
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation established HTTPS communications from adversary-controlled SOHO devices over port 443 with compromised Versa Director servers.

T1074.001
Local Data Staging
MalwareVersaMem

VersaMem staged captured credentials locally at `/tmp/.temp.data`.

T1095
Non-Application Layer Protocol
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation used a non-standard TCP session to initialize communication prior to establishing HTTPS command and control.

T1129
Shared Modules
MalwareVersaMem

VersaMem relied on the Java Instrumentation API and Javassist to dynamically modify Java code existing in memory.

T1190
Exploit Public-Facing Application
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation involved exploitation of a vulnerability in Versa Director servers, since identified as CVE-2024-39717, for initial access and code execution.

T1203
Exploitation for Client Execution
MalwareVersaMem

VersaMem was installed through exploitation of CVE-2024-39717 in Versa Director servers.

T1505.003
Web Shell
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation resulted in the deployment of the VersaMem web shell for follow-on activity.

T1573.002
Asymmetric Cryptography
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation used HTTPS for command and control of compromised Versa Director servers.

T1584.008
Network Devices
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation used compromised small office/home office (SOHO) devices to interact with vulnerable Versa Director servers.

T1587.001
Malware
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation involved the development of a new web shell variant, VersaMem.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.