Malware.View on attack.mitre.org
VersaMem is a web shell designed for deployment to Versa Director servers following exploitation. Discovered in August 2024, VersaMem was used during Versa Director Zero Day Exploitation by Volt Typhoon to target ISPs and MSPs. VersaMem is deployed as a Java Archive (JAR) and allows for credential capture for Versa Director logon activity as well as follow-on execution of arbitrary Java payloads.
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
VersaMem encrypted captured credentials with AES then Base64 encoded them before writing to local storage. |
| T1040 Network Sniffing |
VersaMem hooked the Catalina application filter chain `doFilter` on compromised systems to monitor all inbound requests to the local Tomcat web server, inspecting them for parameters like passwords and follow-on Java modules. |
| T1056.004 Credential API Hooking |
VersaMem hooked and overrided Versa's built-in authentication method, `setUserPassword`, to intercept plaintext credentials when submitted to the server. |
| T1059 Command and Scripting Interpreter |
VersaMem was delivered as a Java Archive (JAR) that runs by attaching itself to the Apache Tomcat Java servlet and web server. |
| T1070.004 File Deletion |
VersaMem deleted files related to initial installation such as temporary files related to the PID of the main web process. |
| T1074.001 Local Data Staging |
VersaMem staged captured credentials locally at `/tmp/.temp.data`. |
| T1129 Shared Modules |
VersaMem relied on the Java Instrumentation API and Javassist to dynamically modify Java code existing in memory. |
| T1203 Exploitation for Client Execution |
VersaMem was installed through exploitation of CVE-2024-39717 in Versa Director servers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.