TunnelVision is an Iranian-aligned intrusion cluster active against organizations in the Middle East and the United States. The actor is characterized by broad exploitation of known vulnerabilities, including CVE-2018-13379, ProxyShell, and Log4Shell in VMware Horizon environments, often followed by extensive use of tunneling utilities such as FRPC and Plink to maintain access and enable remote operations. Reporting has linked the cluster to ransomware deployment, indicating at least some operations have included destructive or extortion-oriented outcomes. In observed VMware Horizon intrusions, TunnelVision exploited Log4j through the Tomcat service to execute PowerShell, establish reverse shells, deploy backdoors, create backdoor administrator accounts, harvest credentials, and move laterally. The actor has used credential dumping techniques including memory dumping and SAM hive collection, and has conducted internal reconnaissance and RDP scanning during post-compromise activity. TunnelVision also leveraged public web services and code-hosting platforms for payload delivery, command relay, and operational support, blending malicious traffic with legitimate services. The cluster has been noted to overlap in part with activity tracked by other vendors as Phosphorus, Charming Kitten, and Nemesis Kitten, but available attribution has been assessed as insufficient to conclude that TunnelVision is identical to those clusters. Its tradecraft is notable for opportunistic exploitation of internet-facing systems, heavy use of tunneling for persistence and access, and practical post-exploitation focused on credential access, lateral movement, and follow-on payload deployment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
A Chinese advanced persistent threat tracked as Deep Panda has been observed exploiting the Log4Shell vulnerability in VMware Horizon servers to deploy a backdoor and a novel rootkit on infected machines with the goal of stealing sensitive data. The latest set of attacks documented by Fortinet shows that the infection procedure involved the exploitation of the Log4j remote code execution flaw (aka Log4Shell) in vulnerable VMware Horizon servers.
During the time we’ve been tracking this actor, we have observed wide exploitation of Fortinet FortiOS (CVE-2018-13379), Microsoft Exchange (ProxyShell) and recently Log4Shell.
During the time we’ve been tracking this actor, we have observed wide exploitation of Fortinet FortiOS (CVE-2018-13379), Microsoft Exchange (ProxyShell) and recently Log4Shell.
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as an Iranian group exploiting Log4Shell in VMware Horizon servers to deploy ransomware.
Iranian-aligned activity cluster conducting wide exploitation of 1-day vulnerabilities, including VMware Horizon Log4j, Fortinet FortiOS, and Microsoft Exchange ProxyShell, followed by PowerShell execution, backdoor deployment, credential harvesting, lateral movement, tunneling tool deployment, and ransomware-linked activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.