tunnelvision
TunnelVision is a SentinelLabs-tracked Iranian-aligned threat actor cluster operating against organizations in the Middle East and the United States. SentinelLabs linked the actor’s activity to ransomware deployment, indicating potentially destructive intent. The cluster is characterized by broad exploitation of known and 1-day vulnerabilities at scale, including Fortinet FortiOS CVE-2018-13379, Microsoft Exchange ProxyShell, and Log4Shell in VMware Horizon environments. In observed VMware Horizon intrusions, TunnelVision exploited Log4j via the Tomcat service to execute PowerShell, deploy backdoors, create backdoor users, harvest credentials, and move laterally. Activity included PowerShell reverse shells, command output exfiltration through webhooks, use of the VMware Horizon NodeJS component for reverse shell execution, reconnaissance, creation of a backdoor user added to the local administrators group, credential harvesting with Procdump, SAM hive dumps, and comsvcs MiniDump, and internal subnet RDP scanning with a public port scanning script. A defining feature of the cluster is heavy use of tunneling tools, especially FRPC and Plink, including downloading and executing Plink and Ngrok to tunnel RDP traffic. SentinelLabs also observed use of legitimate public services including transfer.sh, pastebin.com, webhook.site, ufile.io, raw.githubusercontent.com, and a GitHub repository named VmWareHorizon from the account protections20 to host payloads. Reported infrastructure included command-and-control and payload hosting via domains such as microsoft-updateserver[.]cf and service-management[.]tk. SentinelLabs observed overlap with activity tracked by other vendors as Phosphorus, Charming Kitten, and Nemesis Kitten, but assessed that available attribution data was insufficient to conclude TunnelVision is identical to those clusters.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
Where they're from
Attributed origin per open-source reporting.
- IR
Tradecraft
28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
5 malware families attributed to this actor across reporting.
Associated vulnerabilities
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
During the time we’ve been tracking this actor, we have observed wide exploitation of Fortinet FortiOS (CVE-2018-13379), Microsoft Exchange (ProxyShell) and recently Log4Shell.
During the time we’ve been tracking this actor, we have observed wide exploitation of Fortinet FortiOS (CVE-2018-13379), Microsoft Exchange (ProxyShell) and recently Log4Shell.
In this post, we highlight some of the activities we recently observed from TunnelVision operators, focusing around exploitation of VMware Horizon Log4j vulnerabilities. TunnelVision attackers have been actively exploiting the vulnerability to run malicious PowerShell commands, deploy backdoors, create backdoor users, harvest credentials and perform lateral movement.
Observables
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.