logo

TEST3

ID: dacca1c3-5f84-4989-9991-75de763f893d

STIX ID: report--dacca1c3-5f84-4989-9991-75de763f893d

Threat Score

90/100

Uploaded: 2026-04-08

Published Date: 2026-04-08

Last Modified Date: 2026-04-08

Created by: TEST2 RF

TLP:GREEN
...
...
Mandiant and Google Threat Intelligence Group report that UNC6201 is exploiting a critical zero‑day (CVE‑2026‑22769, CVSS 10.0) in Dell RecoverPoint for Virtual Machines to deploy SLAYSTYLE web shells, maintain persistence, and transition from BRICKSTORM to a new C# AOT backdoor, GRIMBOLT, while pivoting into VMware infrastructures using Ghost NICs and iptables‑based Single Packet Authorization. The report includes technical details of the exploit path via Tomcat Manager default credentials, persistence mechanisms, VMware TTPs, and provides actionable remediation steps, IOCs (hashes and C2), and YARA rules to aid detection and response.