VersaMem is a web shell and in-memory Java implant associated with Volt Typhoon and observed in the Versa Director Zero Day Exploitation activity. It was installed on compromised Versa Director servers through exploitation of CVE-2024-39717 and deployed for follow-on activity. VersaMem was delivered as a Java Archive (JAR) that attaches itself to the Apache Tomcat Java servlet and web server. It relied on the Java Instrumentation API and Javassist to dynamically modify existing Java code in memory. On compromised systems, VersaMem hooked the Catalina application filter chain doFilter method to monitor inbound requests to the local Tomcat web server and inspect them for parameters including passwords and follow-on Java modules. It intercepted and harvested credentials from user logins and staged captured credentials locally at /tmp/.temp.data. The malware is also described as one of several custom web shells used by Volt Typhoon to enable persistent remote access and control.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
VersaMem was installed through exploitation of CVE-2024-39717 in Versa Director servers.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group also deploys custom web shells like Awen, VersaMem, AuditReport, and iisstart.aspx, further enabling persistent remote access and control.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
APT19 downloaded and launched code within a SCT file; APT32 used COM scriptlets to download Cobalt Strike beacons; APT37 used Ruby scripts to execute payloads; ArcaneDoor included the adversary executing command line interface (CLI) commands.
VersaMem was delivered as a Java Archive (JAR) that runs by attaching itself to the Apache Tomcat Java servlet and web server.
"...leveraged the Chrome vulnerability, CVE-2022-0609, in combination with a Drive-by Compromise website." / "...has exploited client software vulnerabilities for execution..." / "...has used multiple software exploits for common client software...to gain code execution."
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Sandworm Team used BlackEnergy’s network sniffer module to discover user credentials being sent over the network...; APT33 has used SniffPass to collect credentials by sniffing network traffic; ArcaneDoor included network packet capture and sniffing...; multiple tools (CASTLETAP, Impacket, Empire, PoshC2, etc.) described as sniffing/packet capture.
Sandworm Team used BlackEnergy’s network sniffer module to discover user credentials being sent over the network...; APT33 has used SniffPass to collect credentials by sniffing network traffic; ArcaneDoor included network packet capture and sniffing...; multiple tools (CASTLETAP, Impacket, Empire, PoshC2, etc.) described as sniffing/packet capture.
"UNC3886 has exploited CVE-2023-34048 to enable command execution on vCenter servers..." / "VersaMem was installed through exploitation of CVE-2024-39717 in Versa Director servers." / "SUPERNOVA was installed via exploitation of a SolarWinds Orion API authentication bypass vulnerability (CVE-2020-10148)."
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool that hooks Tomcat’s filter chain to monitor inbound web requests and inspect for credentials (e.g., passwords) and follow-on modules.
Java-based malware delivered as a JAR that attaches itself to Apache Tomcat for execution.
Java-based malware delivered as a JAR that attaches itself to Apache Tomcat.
Credential-stealing malware that stages captured credentials in a temporary local file.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.