Black Lotus Labs. (2024, August 27). Taking The Crossroads: The Versa Director Zero-Day Exploitaiton. Retrieved August 27, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareVersaMem | VersaMem encrypted captured credentials with AES then Base64 encoded them before writing to local storage. |
| T1040 Network Sniffing |
MalwareVersaMem | VersaMem hooked the Catalina application filter chain `doFilter` on compromised systems to monitor all inbound requests to the local Tomcat web server, inspecting them for parameters like passwords and follow-on Java modules. |
| T1056 Input Capture |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation intercepted and harvested credentials from user logins to compromised devices. |
| T1056.004 Credential API Hooking |
MalwareVersaMem | VersaMem hooked and overrided Versa's built-in authentication method, `setUserPassword`, to intercept plaintext credentials when submitted to the server. |
| T1059 Command and Scripting Interpreter |
MalwareVersaMem | VersaMem was delivered as a Java Archive (JAR) that runs by attaching itself to the Apache Tomcat Java servlet and web server. |
| T1070.004 File Deletion |
MalwareVersaMem | VersaMem deleted files related to initial installation such as temporary files related to the PID of the main web process. |
| T1071.001 Web Protocols |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation established HTTPS communications from adversary-controlled SOHO devices over port 443 with compromised Versa Director servers. |
| T1074.001 Local Data Staging |
MalwareVersaMem | VersaMem staged captured credentials locally at `/tmp/.temp.data`. |
| T1095 Non-Application Layer Protocol |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation used a non-standard TCP session to initialize communication prior to establishing HTTPS command and control. |
| T1129 Shared Modules |
MalwareVersaMem | VersaMem relied on the Java Instrumentation API and Javassist to dynamically modify Java code existing in memory. |
| T1190 Exploit Public-Facing Application |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation involved exploitation of a vulnerability in Versa Director servers, since identified as CVE-2024-39717, for initial access and code execution. |
| T1203 Exploitation for Client Execution |
MalwareVersaMem | VersaMem was installed through exploitation of CVE-2024-39717 in Versa Director servers. |
| T1505.003 Web Shell |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation resulted in the deployment of the VersaMem web shell for follow-on activity. |
| T1573.002 Asymmetric Cryptography |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation used HTTPS for command and control of compromised Versa Director servers. |
| T1584.008 Network Devices |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation used compromised small office/home office (SOHO) devices to interact with vulnerable Versa Director servers. |
| T1587.001 Malware |
CampaignVersa Director Zero Day Exploitation | Versa Director Zero Day Exploitation involved the development of a new web shell variant, VersaMem. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.