Lucene search

K
hiveproHive ProHIVEPRO:753BDE83C1D82672DBEDB937144E1598
HistorySep 16, 2022 - 10:51 a.m.

Monti ransomware infiltrates networks via the well-known Log4Shell

2022-09-1610:51:13
Hive Pro
www.hivepro.com
25

0.975 High

EPSS

Percentile

100.0%

Threat Level Attack Report For a detailed threat advisory, download the pdf file here Summary The Monti ransomware infiltrated the client's internet-facing VMware Horizon virtualization system by exploiting the well-known "Log4Shell" vulnerability, a.k.a. CVE-2021-44228. Furthermore, the threat actor employed a commercial, cloud-based remote monitoring and maintenance (RMM) platform named Action1, which has never been used in a ransomware campaign before.