tunnelvision
TunnelVision is an Iranian-aligned threat actor cluster tracked by SentinelLabs, operating in the Middle East and the US. SentinelLabs assesses the cluster as potentially destructive due to activity linked to ransomware deployment. The actor is notable for heavy reliance on tunneling tools and for broad exploitation of known 1-day vulnerabilities, including Fortinet FortiOS CVE-2018-13379, Microsoft Exchange ProxyShell, Log4Shell, and VMware Horizon Log4j vulnerabilities. In VMware Horizon intrusions, activity was initiated via the Tomcat service process (ws_TomcatService.exe) and used to execute malicious PowerShell, establish reverse shells, deploy backdoors, create backdoor users, harvest credentials, and move laterally. Observed credential access methods included Procdump, SAM hive dumps, and comsvcs MiniDump. The actor also conducted reconnaissance, internal subnet RDP scanning using a publicly available port scan script, and downloaded and executed tunneling tools including FRPC, Plink, and Ngrok to tunnel RDP traffic. TunnelVision used legitimate public services during operations, including transfer.sh, pastebin.com, webhook.site, ufile.io, and raw.githubusercontent.com, including use of webhooks to receive command output from compromised systems. SentinelLabs also reported infrastructure and malware associated with the cluster, including service-management[.]tk hosting malicious payloads, a custom backdoor that dropped InteropServices.exe and registered it as a Windows service named "InteropServices," and use of a GitHub repository named "VmWareHorizon" associated with the account protections20. SentinelLabs noted partial correlation with Microsoft’s Phosphorus activity, while also noting overlap or confusion in vendor reporting with Charming Kitten and Nemesis Kitten. SentinelLabs nevertheless tracks this activity cluster separately as TunnelVision.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
4 malware families attributed to this actor across reporting.
Associated vulnerabilities
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
"we have observed wide exploitation of Fortinet FortiOS (CVE-2018-13379)"
"we have observed wide exploitation of Fortinet FortiOS (CVE-2018-13379), Microsoft Exchange (ProxyShell)"
"and recently Log4Shell" and "focusing around exploitation of VMware Horizon Log4j vulnerabilities."
Observables
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.