Versa Director Zero Day Exploitation is an intrusion campaign centered on exploitation of Versa Director servers through CVE-2024-39717 to obtain initial access and execute code on exposed systems. The activity used adversary-controlled compromised SOHO devices to interact with vulnerable Versa Director infrastructure and established HTTPS-based command-and-control communications with compromised servers. Post-compromise tradecraft included development and deployment of a web shell variant known as VersaMem, indicating sustained post-exploitation access and operator control on affected appliances or management systems. The observed behavior supports a focused exploitation-and-access operation against internet-facing network management infrastructure, with emphasis on stealthy remote control over encrypted channels and use of intermediary edge devices to obscure operator origin.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Activity cluster using HTTPS for command-and-control of compromised Versa Director servers.
Exploitation cluster targeting Versa Director servers via CVE-2024-39717, using compromised SOHO devices to interact with targets, establishing HTTPS C2, and deploying a new web shell (VersaMem) for follow-on activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.