Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
Malware
/
GOREshell
Malware
GOREshell
Indicators of Compromise
2
Domain
reverse_ssh
Filename
reverse_ssh
MITRE ATT&CK TTPs
3
T1053.003
Cron
Execution
T1059.001
PowerShell
Execution
T1071.001
Web Protocols
Command And Control
Source Articles
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
Threat actors are actively exploiting CVE-2026-59310, a critical directory traversal vulnerability in VMware vCenter, to achieve remote code execution and establish persistence via malicious cron jobs. The attackers deploy reverse_ssh, an open-source tool, to create reverse SSH connections to their infrastructure, enabling them to bypass inbound security controls. Forensic evidence from QUIRSO confirms successful compromises beginning August 3, with 361 victim IPs across 47 countries. While the specific actor is not identified, the campaign exhibits characteristics consistent with an advanced persistent threat, and exploitation closely follows public disclosure of the vulnerability.
hacker-news
·
6h ago