VersaMem

S1154

Malware.View on attack.mitre.org

About this malware

VersaMem is a web shell designed for deployment to Versa Director servers following exploitation. Discovered in August 2024, VersaMem was used during Versa Director Zero Day Exploitation by Volt Typhoon to target ISPs and MSPs. VersaMem is deployed as a Java Archive (JAR) and allows for credential capture for Versa Director logon activity as well as follow-on execution of arbitrary Java payloads.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

VersaMem encrypted captured credentials with AES then Base64 encoded them before writing to local storage.

T1040
Network Sniffing

VersaMem hooked the Catalina application filter chain `doFilter` on compromised systems to monitor all inbound requests to the local Tomcat web server, inspecting them for parameters like passwords and follow-on Java modules.

T1056.004
Credential API Hooking

VersaMem hooked and overrided Versa's built-in authentication method, `setUserPassword`, to intercept plaintext credentials when submitted to the server.

T1059
Command and Scripting Interpreter

VersaMem was delivered as a Java Archive (JAR) that runs by attaching itself to the Apache Tomcat Java servlet and web server.

T1070.004
File Deletion

VersaMem deleted files related to initial installation such as temporary files related to the PID of the main web process.

T1074.001
Local Data Staging

VersaMem staged captured credentials locally at `/tmp/.temp.data`.

T1129
Shared Modules

VersaMem relied on the Java Instrumentation API and Javassist to dynamically modify Java code existing in memory.

T1203
Exploitation for Client Execution

VersaMem was installed through exploitation of CVE-2024-39717 in Versa Director servers.

Groups that use it1

Campaigns1

References1

  1. Lumen Versa 2024 Open source
    Black Lotus Labs. (2024, August 27). Taking The Crossroads: The Versa Director Zero-Day Exploitaiton. Retrieved August 27, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.