216.73.216.36

Zyxel vulnerability exploited by 'Helldown' ransomware group

· Published 22/01/2025 09:10 · Modified 22/01/2025 09:46

Export JSON

Essential information

Published
22/01/2025 09:10
Modified
22/01/2025 09:46
Tags
2025-01-22 ransomware vulnerability zyxel
Related entities
1 intrusion sets (apt), 16 techniques (mitre), 5 malware, 2 others

Description

The article details a cybersecurity incident where the "Helldown" group exploited a in firewall devices. The attackers gained administrator access to the firewall console, collected domain credentials, and compromised the infrastructure. They used VPN services to mask their origin and created additional users for persistent access. The threat actors employed tools like Advanced IP Scanner and Mimikatz for network discovery and credential theft. Multiple variants were deployed, encrypting both Windows and ESXi systems. The attack methodology included manual commands on the ESXi server to terminate VM processes before encryption. The article provides a comprehensive breakdown of the attack chain, including IP addresses, malware files, and MITRE ATT&CK techniques used by the Helldown group.

External references