VersaMem
MITRE ATT&CK: S1154 View on attack.mitre.org
Aliases: VersaMem
- First seen
- 2024-08-01 00:00:00
- Malware type
- webshell
- Family
- Malware family
- Operating systems
- network-devices
- Profile updated
- 2026-07-07 14:32:29
Targeted industries: technology-and-telecommunications
Context
VersaMem is a web shell designed for deployment to Versa Director servers following exploitation. Discovered in August 2024, VersaMem was used during Versa Director Zero Day Exploitation by Volt Typhoon to target ISPs and MSPs. VersaMem is deployed as a Java Archive (JAR) and allows for credential capture for Versa Director logon activity as well as follow-on execution of arbitrary Java payloads.
Detection coverage
- 1 YARA rules
- 120 Sigma rules
Malware & tools used
- Credential API Hooking (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- File Deletion (attack-pattern)
- Command and Scripting Interpreter (attack-pattern)
- Local Data Staging (attack-pattern)
- Network Sniffing (attack-pattern)
- Shared Modules (attack-pattern)
Used by threat actors
- Volt Typhoon (threat-actor)
- Versa Director Zero Day Exploitation (campaign)
Detection rules
- SIGNATURE_BASE_WEBSHELL_JAVA_Versamem_JAR_Aug24_1 (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Jar.Versamem (report)
- blog.lumen.com — Taking The Crossroads The Versa Director Zero Day Exploitation (report)
- MITRE ATT&CK — S1154 (report)