APT Reverse-SSH Persistence After vCenter CVE-2026-59310 (CVSS 9.8) Exploitation
On August 3, 2026, an APT campaign began mass-exploiting CVE-2026-59310 (CVSS 9.8), a directory-traversal flaw in VMware vCenter Server patched by Broadcom in late July. Security firm Quirso has since observed victims across 47 countries and 361 IP addresses, with Germany, the United States, Turkey, Iran, and France hardest hit; operators chain the traversal into arbitrary code execution and hold onto compromised hypervisor management planes via reverse-SSH tunnels, and Broadcom stresses there are no mitigations other than applying its updates. This demo reproduces the Linux-side persistence pattern such operators rely on after the initial compromise: a payload script that drops an XDG autostart entry (the Linux counterpart of a Windows Run key) so a reverse-SSH tunnel re-establishes at every login. MetaDefender Adaptive Sandbox executes the payload in isolation, observes the autostart write and tunnel-setup behavior, and reports the full persistence mechanism with its command line — exposing the implant before it ever reaches production virtualization infrastructure.
Attack Technique
Persistence via XDG autostart entry maintaining a reverse-SSH tunnel foothold (APT pattern after CVE-2026-59310 vCenter exploitation)
MITRE ATT&CK
T1547.001 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗