TunnelVision is an Iranian-aligned intrusion cluster associated with exploitation of internet-facing enterprise systems, especially known-vulnerable edge infrastructure, followed by extensive post-compromise tunneling and remote access activity. The group has been observed targeting organizations in the Middle East and the United States and has been linked to intrusions affecting government environments as well as ransomware deployment. The actor is characterized by broad exploitation of n-day and recently disclosed vulnerabilities, including CVE-2018-13379 in Fortinet FortiOS, ProxyShell in Microsoft Exchange, and Log4Shell against VMware Horizon. In VMware Horizon compromises, TunnelVision has used Log4j exploitation through Tomcat-related processes to execute PowerShell, deploy backdoors, establish reverse shells, create backdoor accounts, harvest credentials, and move laterally across victim networks. A defining operational trait is heavy use of tunneling and remote access tooling, particularly FRPC, Plink, and Ngrok, often to facilitate remote desktop access and post-exploitation persistence. Reported tradecraft also includes reconnaissance, internal RDP scanning, credential dumping via memory and SAM-hive access, creation of privileged accounts, and use of legitimate public services for payload staging, command relay, and operational support. TunnelVision has also been associated with cryptomining payload delivery in at least one intrusion chain. Attribution reporting consistently places TunnelVision within the broader Iranian threat ecosystem. Its activity overlaps with clusters tracked by various vendors as Phosphorus, Charming Kitten, and Nemesis Kitten, but available evidence does not conclusively establish that TunnelVision is identical to any one of those groups. The dominant pattern is an Iran-linked actor focused on opportunistic exploitation, durable access, and follow-on malicious operations including ransomware-related activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
CISA and the FBI issued a joint advisory warning of ongoing exploitation of the Log4Shell vulnerability (CVE-2021-44228) on November 16. The advisory noted that an unspecified Iran-linked threat actor group had exploited the vulnerability during an intrusion into a Federal Civilian Executive Branch (FCEB) organization’s network earlier this year.
During the time we’ve been tracking this actor, we have observed wide exploitation of Fortinet FortiOS (CVE-2018-13379), Microsoft Exchange (ProxyShell) and recently Log4Shell.
During the time we’ve been tracking this actor, we have observed wide exploitation of Fortinet FortiOS (CVE-2018-13379), Microsoft Exchange (ProxyShell) and recently Log4Shell.
21 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Assessed as responsible for exploiting Log4Shell (CVE-2021-44228) against a U.S. Federal Civilian Executive Branch organization via vulnerable VMware Horizon, followed by PowerShell-based payload delivery, XMRig deployment, Ngrok use, lateral movement over RDP, credential harvesting, and creation of a new domain administrator account.
Mentioned as an Iranian group exploiting Log4Shell in VMware Horizon servers to deploy ransomware.
Iranian-aligned activity cluster conducting wide exploitation of 1-day vulnerabilities, including VMware Horizon Log4j, Fortinet FortiOS, and Microsoft Exchange ProxyShell, followed by PowerShell execution, backdoor deployment, credential harvesting, lateral movement, tunneling tool deployment, and ransomware-linked activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.