Skip to main content
← Back to Demos
Malware intermediate · 15 min

APT Reverse-SSH Persistence After vCenter CVE-2026-59310 (CVSS 9.8) Exploitation

On August 3, 2026, an APT campaign began mass-exploiting CVE-2026-59310 (CVSS 9.8), a directory-traversal flaw in VMware vCenter Server patched by Broadcom in late July. Security firm Quirso has since observed victims across 47 countries and 361 IP addresses, with Germany, the United States, Turkey, Iran, and France hardest hit; operators chain the traversal into arbitrary code execution and hold onto compromised hypervisor management planes via reverse-SSH tunnels, and Broadcom stresses there are no mitigations other than applying its updates. This demo reproduces the Linux-side persistence pattern such operators rely on after the initial compromise: a payload script that drops an XDG autostart entry (the Linux counterpart of a Windows Run key) so a reverse-SSH tunnel re-establishes at every login. MetaDefender Adaptive Sandbox executes the payload in isolation, observes the autostart write and tunnel-setup behavior, and reports the full persistence mechanism with its command line — exposing the implant before it ever reaches production virtualization infrastructure.

Attack Technique

Persistence via XDG autostart entry maintaining a reverse-SSH tunnel foothold (APT pattern after CVE-2026-59310 vCenter exploitation)

MITRE ATT&CK

T1547.001 ↗

Platforms

linuxwindows

File Types

.sh.cmd

MetaDefender Capabilities

MetaDefender Sandbox

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---