EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

Malicious Cyber Actors Continue to Exploit Log4Shell in VMware Horizon Systems

Official source
EudorIA operational summary

What it means

Priority 95/100

CISA Cybersecurity Advisories ha pubblicato l'advisory "Malicious Cyber Actors Continue to Exploit Log4Shell in VMware Horizon Systems". La fonte segnala sfruttamento attivo e richiede una verifica prioritaria.

Why it matters

La fonte segnala sfruttamento attivo. La priorita dipende dalla presenza della tecnologia interessata nel perimetro; il testo acquisito non consente di dedurre ulteriori impatti tecnici.

Potential operational benefits

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
AudienceITSOCCISO
Information centre

Translation in progress

CISA

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs. Cybersecurity Advisory Malicious Cyber Actors Continue to Exploit Log4Shell in VMware Horizon Systems Last Revised July 18, 2022 Alert Code AA22-174A Summary Actions to take today: • Install fixed builds, updating all affected VMware Horizon and UAG systems to the latest versions. If updates or workarounds were not promptly applied following VMware’s release of updates for Log4Shell in December 2021, treat all affected VMware systems as compromised. • Minimize the internet-facing attack surface by hosting essential services on a segregated demilitarized (DMZ) zone, ensuring strict network perimeter access controls, and implementing regularly updated web application firewalls (WAFs) in front of public-facing services The Cybersecurity and Infrastructure Security Agency (CISA) and United States Coast Guard Cyber Command (CGCYBER) are releasing this joint Cybersecurity Advisory (CSA) to warn network defenders that cyber threat actors, including state-sponsored advanced persistent threat (APT) actors, have continued to exploit CVE-2021-44228 (Log4Shell) in VMware Horizon® and Unified Access Gateway (UAG) servers to obtain initial access to organizations that did not apply available patches or workarounds. Since December 2021, multiple threat actor groups have exploited Log4Shell on unpatched, public-facing VMware Horizon and UAG servers. As part of this exploitation, suspected APT actors implanted loader malware on compromised systems with embedded executables enabling remote command and control (C2). In one confirmed compromise, these APT actors were able to move laterally inside the network, gain access to a disaster recovery n

Indicatori CISA verificabili

43 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Ultima verifica: 2026-09-26T09:03:14.359204+00:00

Scarica STIX 2.1
TipoIndicatore (non cliccabile)File
ipv4-addr104[.]155[.]149[.]103
ipv4-addr185[.]136[.]163[.]104
ipv4-addr134[.]119[.]177[.]107
ipv4-addr109[.]248[.]150[.]13
ipv4-addr155[.]94[.]211[.]207
ipv4-addr162[.]245[.]190[.]203
ipv4-addr92[.]222[.]241[.]76
ipv4-addr192[.]95[.]20[.]8
ipv4-addr104[.]223[.]34[.]198

Provenance

Allegato ufficiale CISA · 2022-06-24T18:31:15Z

SHA-512: 807984f5119b2f0a82ffb85bcdf9386b1a042e476a6ac14ff046677903973e11a947d25bb372d103b952cb21584f2ede1a8883429346187ace9cf4cd789d611a

TipoIndicatore (non cliccabile)File
MD5df81145680b4deab198d9bba091d86e9
SHA-14235d9a934d26ec688c21e3fc2e470178b7b3c21
SHA-2566589a687e69a182e075f11805a755ac1fabbddae1636c6fea8e80e7414521349
MD5f9e6ca0bdaa43df9ed0449b964e1b8b4
SHA-124b983856dfdd4e48eeeafc9372b70d6b53ae722
SHA-2566e3840f11aa02f391edd7e3e65b214f1af128fa207b4feb7f69e438014a2206d
ipv4-addr192[.]95[.]20[.]8

Provenance

Allegato ufficiale CISA · 2022-06-03T19:14:20Z

SHA-512: ec1dc07ae3b0ede9d938e460a6fee745642c6a8580c1c9e76adaf26a77448d42629e50115bbd5a66a35da9983ed791bca4603742d3397aac24d3401dc06e9a97

TipoIndicatore (non cliccabile)File
MD521fa1a043460c14709ef425ce24da4fd
SHA-133638da3a83c2688e1d20862b1de0b242a22e87c
SHA-25666966ceae7e3a8aace6c27183067d861f9d7267aed30473a95168c3fe19f2c16
ipv4-addr185[.]136[.]163[.]104
MD57b1ce3fe542c6ae2919aa94e20dc860e
SHA-149a5852783fcefd9513b02d27a0304ae171f4459
SHA-256d071c4959d00a1ef9cce535056c6b01574d8a8104a7c3b00a237031ef930b10f
MD5de0d57bdc10fee1e1e16e225788bb8de
SHA-1695d31cdac532be8e6d2a98220c0c55f3385aa0b
SHA-25633b89b8915aaa59a3c9db23343e8c249b2db260b9b10e88593b6ff2fb5f71d2b
ipv4-addr134[.]119[.]177[.]107
MD5e9c2b8bd1583baf3493824bf7b3ec51e
SHA-176f2c5f0312346caf82ed42148e78329f8d7b35a
SHA-2567ea294d30903c0ab690bc02b64b20af0cfe66a168d4622e55dee4d6233783751
ipv4-addr162[.]245[.]190[.]203
MD59b071311ecd1a72bfd715e34dbd1bd77
SHA-14a3f79d6821139bc1c3f44fb32e8450ee9705237
SHA-2563c2c835042a05f8d974d9b35b994bcf8d5a0ce19128ebb362804c2d0f3eb42c0
ipv4-addr155[.]94[.]211[.]207
MD53e200093f737fcd1e4bd350f6ffb7d56
SHA-10e9e98d93463798645cc0a972a4ff6f99977318a
SHA-25628e4e7104cbffa97a0aa2f53b5ebcbcdba360ec416b34bb617e2f8891d204816
MD53764a0f1762a294f662f3bf86bac776f
SHA-16a87d8df99ea58d8612fa58a58b1a3a9512f160e
SHA-256f7f7b059b6a7dbd75b30b685b148025a0d4ceceab405e553ca28cacdeae43fab
MD5199a32712998c6d736a05b2dbd24a761
SHA-145e0d90bd0283a1262d5afff46232e0ad4227d3b
SHA-25688a5e4b24747648a4e3f0a2d5282b51683260f9208b06788fc858c44559da1e8

Provenance

Allegato ufficiale CISA · 2022-06-03T18:28:03Z

SHA-512: b7fe8d9c874e9cf802d5afaf15460833094eef830c3d1dfb1006441e1edd378e2563c17f94dc7dff170630f8efa6c0d64078c1fffa137e5a7f62e86e2440b4e8

TipoIndicatore (non cliccabile)File
MD505d38bc82d362dd57190e3cb397f807d
SHA-152b04d348adf7e42e7c7d6c2ec9aabbcaba07188
SHA-2564cd7efdb1a7ac8c4387c515a7b1925931beb212b95c4f9d8b716dbe18f54624f
ipv4-addr151[.]106[.]30[.]120

Provenance

Allegato ufficiale CISA · 2022-07-11T16:39:56Z

SHA-512: 7f0fa8b27be2ebc33d17105240ba6568ba36690fbcd7a7c19f0906c207d54c5237fdd77e889c9d5d6df08117f917a4b7cb791c26f46a40588b1c33e0fe27247e

Source
CISA Cybersecurity Advisories
Publishing entity
CISA
Entity type
National authority
Area
North America · US
Original language
en · translation in preparation
Publication
18/07/2022 14:00
Sharing
TLP:CLEAR
MITRE ATT&CK
T1021.001, T1036.004, T1053.005, T1056.001, T1059.001, T1071.001, T1090, T1105, T1190, T1505.003, T1560.001, T1571, T1573.001, T9803
CVE
CVE-2021-44228, CVE-2022-22954, CVE-2022-22960
Stated country
US
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Action indicated by the source

Verificare l'applicabilita dell'advisory e applicare le mitigazioni ufficiali.

Official technical references

Open the original source