Threat actors, including suspected state-sponsored groups, continued exploiting Log4Shell (CVE-2021-44228) in unpatched public-facing VMware Horizon and Unified Access Gateway systems, according to a joint CISA and U.S. Coast Guard Cyber Command advisory. In confirmed incidents, attackers used the flaw for initial access, deployed malware disguised as SysInternals tools, established command-and-control, moved laterally over RDP, and in at least one case reached a disaster recovery network and exfiltrated sensitive data. The advisory highlighted artifacts including hmsvc.exe, SvcEdge.exe, odbccads.exe, praiser.exe, fontdrvhosts.exe, winds.exe, error_401.jsp, and newdev.dll, and urged organizations that delayed patching to assume compromise, isolate affected hosts, hunt for indicators, and upgrade to fixed VMware builds.
The vulnerability’s broad reach and difficult-to-observe execution paths also drove a wave of defensive tooling and monitoring guidance across the security community. Researchers released a Burp Suite Log4Shell Scanner that uses out-of-band DNS and LDAP-based callbacks to uncover hidden or asynchronous vulnerable services, while others published Suricata detection coverage, regex-based IOC matching for log review, and updated enterprise advisories from vendors including Red Hat, Sophos, Mandiant, and SANS. Reports also indicated exploitation activity had begun early, with botnets attempting to weaponize the flaw soon after disclosure, reinforcing that Log4Shell remained both a mass-scanning target and a high-impact intrusion vector long after patches became available.

See which actors are running it and whether you're in range.
20 events from the most recent confirmed update back to the earliest known activity.
Mandiant published guidance on initial Log4Shell exploitation and mitigation recommendations, summarizing defensive considerations for organizations still managing the risk.
SC Media published a feature examining the numbers and impact one year after Log4Shell, marking a retrospective milestone in coverage of the vulnerability.
The log4shell-rex GitHub project was published to provide PCRE regex matching for Log4Shell indicators of compromise in logs.
Red Hat issued critical advisory RHSA-2021:5107, releasing OpenShift Container Platform 4.7.40 to remediate Log4Shell (CVE-2021-44228), CVE-2021-4104, and CVE-2021-45046. The update applied to OCP 4.6 and 4.7 deployments on RHEL 8 for x86_64, ppc64le, and s390x.
Red Hat issued critical advisory RHSA-2021:5148 for OpenShift Container Platform 4.8.24 extras, updating packages and images to address Log4Shell (CVE-2021-44228). The advisory also remediated CVE-2021-4104 and CVE-2021-45046 for affected RHEL 8 x86_64, ppc64le, and s390x deployments.
Red Hat issued critical advisory RHSA-2021:5138, releasing Red Hat AMQ Streams 1.8.4 to replace version 1.8.0 and remediate CVE-2021-44228 in log4j-core. The update included security fixes, bug fixes, and enhancements.
Red Hat issued critical advisory RHSA-2021:5133, releasing AMQ Streams 1.6.5 to replace version 1.6.4 and remediate CVE-2021-44228 in log4j-core. The update included security fixes, bug fixes, and enhancements.
Red Hat issued critical advisory RHSA-2021:5108 for Red Hat OpenShift Container Platform 4.8.z, remediating CVE-2021-44228 in log4j-core. The update affected RHEL 8 deployments on x86_64, ppc64le, and s390x architectures and also referenced CVE-2021-45046.
Red Hat issued fixes for CVE-2021-44228 affecting OpenShift Logging Elasticsearch components, AMQ Streams, Data Grid 8.2.2, Fuse 7.10, and Red Hat Integration. The OpenShift Logging fixes were released through RHSA-2021:5127, RHSA-2021:5128, RHSA-2021:5129, and RHSA-2021:5137.
Neo23x0 published Fenrir version 0.9.0 as a Log4Shell-focused release, adding tooling relevant to detection or response for the vulnerability.
A GitHub Gist published Suricata coverage for Log4Shell exploitation attempts, providing defenders with detection content for CVE-2021-44228 activity.
Silent Signal announced and released an open-source Burp Suite extension called Log4Shell Scanner to help defenders identify hidden Log4Shell-affected hosts using out-of-band detection.
SANS Internet Storm Center published follow-up content describing what it was seeing from Log4Shell activity and how defenders could respond and access related data.
Red Hat published security bulletin RHSB-2021-009 covering the Log4Shell remote code execution vulnerability in log4j and related response guidance.
ZDNet reported that remote code execution activity targeting Log4Shell began on 2021-12-01, with botnets starting to use the vulnerability before its broad public disclosure.
Red Hat issued RHSA-2025:1746 for JBoss Enterprise Application Platform 7.1 EUS on RHEL 7 and RHSA-2025:1747 for EAP 7.3 EUS on RHEL 7 to address CVE-2021-44228.
Red Hat issued 2022 advisories addressing CVE-2021-45046 for Fuse, Data Grid, Vert.x, EAP 7.4 Log4j Async, and Red Hat Integration Camel products. The advisories remediated the incomplete Log4Shell fix affecting certain non-default Log4j Pattern Layout configurations.
CISA and U.S. Coast Guard Cyber Command issued a joint advisory stating that multiple threat actors, including suspected state-sponsored actors, continued exploiting unpatched VMware Horizon and Unified Access Gateway systems after fixes became available in December 2021. The advisory also documented two confirmed incident-response cases involving malware deployment, lateral movement, and in one case data exfiltration.
Red Hat documented CVE-2021-4104, a moderate Log4j 1.x JMSAppender vulnerability that can enable JNDI-based code execution only when a non-default configuration is enabled and trusted configuration or runtime properties can be modified. Red Hat issued product-specific advisories for affected RHEL, OpenShift, JBoss, middleware, and related products, while noting that Log4j 1.x is end of life.
Red Hat documented that Log4j 2.15.0's remediation for CVE-2021-44228 was insufficient for certain non-default Pattern Layout configurations containing Context Lookups. The issue affects Log4j 2.0 through 2.15; Log4j 2.16.0 removes message lookup patterns and disables JNDI by default, and CodeReady Studio 12.21.3 and later include a fix.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
27 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcesophos.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcezdnet.com
Open sourcedocs.openshift.com
Open sourcedocs.openshift.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.