ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Exploits

Volt Typhoon APT Exploits Zero-Day Vulnerability (CVE-2024-39717) in Versa Director

Kyle by Kyle
August 27, 2024
in Exploits
Reading Time: 3 mins read
Image of Chinese hackers
Share on FacebookShare on Twitter

The China-linked Advanced Persistent Threat (APT) group known as Volt Typhoon has been discovered exploiting a zero-day vulnerability in Versa Director, a critical network management platform. This development highlights the ongoing cybersecurity threats faced by critical infrastructure sectors.

The Vulnerability: CVE-2024-39717

The zero-day vulnerability, CVE-2024-39717, affects the “Change Favicon” feature in Versa Director’s graphical user interface (GUI). This flaw allows authenticated users with specific privileges to upload malicious files disguised as PNG images. Versa Networks, the company behind Versa Director, has confirmed at least one instance of the vulnerability being exploited due to a customer’s failure to implement recommended firewall guidelines.

Versa Director: A Critical Target

Versa Director is a centralized management and orchestration platform primarily used by Internet Service Providers (ISPs) and Managed Service Providers (MSPs) to manage Software-Defined Wide Area Networks (SD-WANs). The platform’s critical role in network infrastructure makes it an attractive target for cyber attackers.

Discovery and Analysis

Researchers at Lumen’s Black Lotus Labs discovered the vulnerability on June 17, 2024. They identified a malicious Java binary named “VersaTest.png” uploaded from Singapore to VirusTotal. Further analysis revealed this file as a custom Java web shell, internally called “Director_tomcat_memShell” and dubbed “VersaMem” by the researchers.

VersaMem: A Sophisticated Web Shell

VersaMem is a highly sophisticated, custom-tailored JAR web shell specifically designed to target Versa Director systems. Key features of VersaMem include:

  • Built using Apache Maven on June 3, 2024
  • Attaches to the Apache Tomcat process upon execution
  • Uses Java Instrumentation API and Javassist toolkit for in-memory code modification
  • Captures plaintext user credentials
  • Dynamically loads Java classes in memory
  • Operates entirely in memory to avoid detection

Versa Director exploitation process from Lumen

Exploitation Campaign

Black Lotus Labs detected unusual traffic patterns indicating the exploitation of several U.S. Versa Director servers between June 12 and mid-July 2024. The researchers identified five victims, four in the U.S. and one outside, primarily in the ISP, MSP, and IT sectors. The earliest exploitation was detected at a U.S. ISP on June 12, 2024.

Volt Typhoon: A Persistent Threat

Volt Typhoon has been active since at least mid-2021, focusing on cyber operations against critical infrastructure. The group has targeted organizations in various sectors, including:

You might also like

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

Critical Vulnerabilities Exposed in Ruijie Networks Cloud Platform

  • Communications
  • Manufacturing
  • Utility
  • Transportation
  • Construction
  • Maritime
  • Government
  • Information Technology
  • Education

Tactics and Techniques

Volt Typhoon is known for its sophisticated approach to cyberattacks:

  • Extensive use of living-off-the-land techniques
  • Hands-on-keyboard activity to evade detection
  • Routing malicious traffic through compromised SOHO network devices
  • Reliance on customized versions of open-source tools for command and control (C2) communications

Implications for Critical Infrastructure

U.S. agencies have expressed concern about Volt Typhoon’s activities, particularly the potential for the group to:

  • Gain access to critical infrastructure networks
  • Cause disruptive effects during geopolitical tensions or military conflicts
  • Establish footholds within networks to secure access to Operational Technology (OT) assets

Mitigation and Response

In response to the threat posed by Volt Typhoon, U.S. agencies have released a technical guide containing recommendations on how to identify and mitigate the living off the land techniques adopted by the APT group. Organizations using Versa Director are urged to implement the recommended firewall guidelines and keep their systems updated.

Tags: chinaVolt Typhoon
Previous Post

China-Linked APT Group Velvet Ant Exploits Cisco Zero-Day (CVE-2024-20399) Vulnerability

Next Post

Seattle-Tacoma International Airport Paralyzed by Cyberattack: Systems Disrupted for Third Day

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Photo of the CISCO logo and text saying "You have been hacked!"

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

March 6, 2026
What is DoubleClickJacking?

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

Critical Vulnerabilities Exposed in Ruijie Networks Cloud Platform

December 25, 2024

Vulnerability (CVE-2024-54143 ) Discovered in OpenWrt’s Firmware Upgrade System

December 13, 2024

Cybercriminals Unleash Advanced Phishing-as-a-Service Toolkit Targeting Microsoft 365 Users

November 29, 2024

Major Security Vulnerability Uncovered in qBittorrent Client

November 1, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.