An Iran-linked threat actor assessed as TunnelVision exploited the Log4Shell vulnerability (CVE-2021-44228) in VMware Horizon to compromise a U.S. federal civilian agency, according to reporting that ties the activity to broader Iranian intrusion operations. Researchers said the intrusion matched a campaign previously observed in the wild and aligned with government warnings that Iranian operators were actively abusing the flaw in internet-facing Horizon systems.
The intrusion reportedly began from 51.89.181[.]64 and involved follow-on communication with 182.54.217[.]2 and us-nation-ny[.]cf, followed by PowerShell payload delivery, XMRig cryptomining, Ngrok tunneling, lateral movement over RDP, credential harvesting, and the creation of a new domain administrator account. SecurityScorecard assessed with moderate confidence that TunnelVision was responsible based on infrastructure and tradecraft overlaps, while Microsoft has separately linked related Iranian ransomware activity to DEV-0270 / PHOSPHORUS, reinforcing the view that the operation fits within a broader Iran-aligned threat cluster despite ongoing attribution ambiguity among groups such as Charming Kitten and Nemesis Kitten.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
SecurityScorecard analyzed the advisory's indicators and assessed with moderate confidence that TunnelVision was responsible for the intrusion. It cited overlaps in infrastructure and tradecraft with the February 2022 VMware Horizon exploitation and suggested a connection to the broader Iranian cluster Phosphorus.
Microsoft Threat Intelligence published research profiling DEV-0270 and associating its ransomware operations with PHOSPHORUS. The excerpt provides attribution but no additional operational details.
CISA conducted an incident response engagement tied to the federal intrusion during June and July 2022. Investigators found the attackers had exploited a vulnerable VMware Horizon server, used PowerShell payloads, deployed XMRig, used Ngrok and RDP, harvested credentials, and created a new domain administrator account.
A federal intrusion detection system first detected an intrusion into an unspecified Federal Civilian Executive Branch organization. The later advisory said an Iran-linked threat actor had exploited Log4Shell in VMware Horizon during this incident.
A SentinelOne report documented Iranian-aligned threat actor TunnelVision actively exploiting the Log4Shell vulnerability in VMware Horizon. The activity used infrastructure including 182.54.217[.]2 and tradecraft such as PowerShell and Ngrok.
CISA and the FBI issued a joint advisory on November 16 warning that an Iran-linked threat actor was actively exploiting Log4Shell in VMware Horizon. The advisory described the earlier intrusion into a Federal Civilian Executive Branch organization and published related indicators of compromise.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
securityscorecard.com
Open sourcemicrosoft.com
Open sourcesentinelone.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.