August 27th, 2024

Hackers infect ISPs with malware that steals customers' credentials

Hackers linked to the Chinese government exploited a zero-day vulnerability in the Versa Director platform, affecting U.S. ISPs, allowing credential capture via malware before hashing. The vulnerability was patched.

Read original articleLink Icon
Hackers infect ISPs with malware that steals customers' credentials

Hackers, likely affiliated with the Chinese government, have exploited a critical zero-day vulnerability in the Versa Director platform, affecting at least four U.S.-based Internet Service Providers (ISPs). This vulnerability, tracked as CVE-2024-39717, allows attackers to install a custom web shell named "VersaMem," which grants them remote administrative control over the affected systems. The exploitation began around June 12, 2024, and enables the malware to capture customer credentials before they are securely hashed. The attackers gained initial access through an exposed management port, which was not properly secured according to Versa's guidelines. The vulnerability was patched by Versa after being reported by Lumen's Black Lotus Labs, which noted the sophistication of the threat actors and the potential consequences of such breaches. The report emphasizes the significance of this exploitation campaign, given the critical role of the Versa Director servers in managing network infrastructures. Black Lotus Labs identified several anomalous traffic patterns that indicated successful exploitation, including compromised small office and home office routers.

- Hackers exploited a zero-day vulnerability in the Versa Director platform used by ISPs.

- The malware, named "VersaMem," captures customer credentials before they are hashed.

- Initial access was gained through an unsecured management port.

- The vulnerability was patched after being reported by Lumen's Black Lotus Labs.

- The campaign is considered highly significant due to its potential impact on customer security.

Link Icon 5 comments
By @corytheboyd - 5 months
Been feeling like it’s the beginning of the end for a while now… I have good security hygiene, but I am sure enough of my sensitive info has been leaked by various “trusted authorities” (I mean, fucking Equifax) that someone could ruin my life if they wanted to. You just stay vigilant and hope that doesn’t happen I guess.
By @a5withtrrs - 5 months
My speculation on this is that China/Russia/whoever targets ISP's in order to identify people by IP that have come to their attention somehow. Your credentials aren't the only point of interest, your credentials gives up subscriber information name/email/address/etc. That's pretty valuable from an intelligence standpoint.
By @ChrisArchitect - 5 months
By @ikekkdcjkfke - 5 months
Rising discord and worshipping money
By @2OEH8eoCRo0 - 5 months
When are we going to start taking this seriously?