VersaMem — Malware Profile
VersaMem is a web shell designed for deployment to Versa Director servers following exploitation. Discovered in August 2024, VersaMem was used during Versa Director Zero Day Exploitation by Volt Typhoon to target ISPs and MSPs. VersaMem is deployed as a Java Archive (JAR) and allows for credential capture for Versa Director logon activity as well as follow-on execution of arbitrary Java payloads.
MITRE ATT&CK techniques (8)
- T1027.013 Encrypted/Encoded File
- T1040 Network Sniffing
- T1056.004 Credential API Hooking
- T1059 Command and Scripting Interpreter
- T1070.004 File Deletion
- T1074.001 Local Data Staging
- T1129 Shared Modules
- T1203 Exploitation for Client Execution