VersaMem

MITRE ATT&CK: S1154 View on attack.mitre.org

Aliases: VersaMem

First seen
2024-08-01 00:00:00
Malware type
webshell
Family
Malware family
Operating systems
network-devices
Profile updated
2026-07-07 14:32:29

Targeted industries: technology-and-telecommunications

Context

VersaMem is a web shell designed for deployment to Versa Director servers following exploitation. Discovered in August 2024, VersaMem was used during Versa Director Zero Day Exploitation by Volt Typhoon to target ISPs and MSPs. VersaMem is deployed as a Java Archive (JAR) and allows for credential capture for Versa Director logon activity as well as follow-on execution of arbitrary Java payloads.

Detection coverage

  • 1 YARA rules
  • 120 Sigma rules

Malware & tools used

  • Credential API Hooking (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • File Deletion (attack-pattern)
  • Command and Scripting Interpreter (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Network Sniffing (attack-pattern)
  • Shared Modules (attack-pattern)

Used by threat actors

  • Volt Typhoon (threat-actor)
  • Versa Director Zero Day Exploitation (campaign)

Detection rules

  • SIGNATURE_BASE_WEBSHELL_JAVA_Versamem_JAR_Aug24_1 (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Jar.Versamem (report)
  • blog.lumen.com — Taking The Crossroads The Versa Director Zero Day Exploitation (report)
  • MITRE ATT&CK — S1154 (report)

External references