TEST3
ID: dacca1c3-5f84-4989-9991-75de763f893d
STIX ID: report--dacca1c3-5f84-4989-9991-75de763f893d
Threat Score
90/100
Uploaded: 2026-04-08
Published Date: 2026-04-08
Last Modified Date: 2026-04-08
Created by: TEST2 RF
TLP:GREEN
...
...
Mandiant and Google Threat Intelligence Group report that UNC6201 is exploiting a critical zero‑day (CVE‑2026‑22769, CVSS 10.0) in Dell RecoverPoint for Virtual Machines to deploy SLAYSTYLE web shells, maintain persistence, and transition from BRICKSTORM to a new C# AOT backdoor, GRIMBOLT, while pivoting into VMware infrastructures using Ghost NICs and iptables‑based Single Packet Authorization. The report includes technical details of the exploit path via Tomcat Manager default credentials, persistence mechanisms, VMware TTPs, and provides actionable remediation steps, IOCs (hashes and C2), and YARA rules to aid detection and response.
