Connect with us

GRTech

Sophos Uncovers Backdoors Attackers Leverage to Attack VMware Horizon servers, Sophos Finds

Sophos Finds Three Backdoors, Possibly Delivered by Initial Access Brokers, and Four Cryptominers Targeting Unpatched VMware Horizon Servers, reports SANDRA ANI

Published

on

Log4J

Sophos, a global leader in next-generation cybersecurity, today released findings on how attackers are using the Log4Shell vulnerability to deliver backdoors and profiling scripts to unpatched VMware Horizon servers, paving the way for persistent access and future ransomware attacks.

A new technical paper, “Horde of Miner Bots and Backdoors Leveraged Log4J to Attack VMware Horizon Servers,” details the tools and techniques used to compromise the servers and deliver three different backdoors and four cryptominers. The backdoors are possibly delivered by Initial Access Brokers.

Log4Shell is a remote code execution vulnerability in the Java logging component, Apache Log4J, which is embedded in hundreds of software products. It was reported and patched in December 2021.

“Widely used applications such as VMware Horizon that are exposed to the internet and need to be manually updated, are particularly vulnerable to exploitation at scale,” said Sean Gallagher, senior security researcher at Sophos. “Sophos detections reveal waves of attacks targeting Horizon servers, starting in January, and delivering a range of backdoors and cryptominers to unpatched servers, as well as scripts to collect some device information. Sophos believes that some of the backdoors may be delivered by Initial Access Brokers looking to secure persistent remote access to a high value target that they can sell on to other attackers, such as ransomware operators.”

Cybersecurity by Sophos

Cybersecurity by Sophos

The multiple attack payloads Sophos detected using Log4Shell to target vulnerable Horizon servers include:

  • Two legitimate remote monitoring and management tools, Atera agent and Splashtop Streamer, likely intended for malicious use as backdoors
  • The malicious Sliver backdoor
  • The cryptominers z0Miner, JavaX miner, Jin and Mimu
  • Several PowerShell-based reverse shells that collect device and backup information

Sophos’ analysis revealed that Sliver is sometimes delivered together with Atera and PowerShell profiling scripts and is used to deliver the Jin and Mimu variants of the XMrig Monero miner botnet.

According to Sophos, the attackers are using several different approaches to infect targets. While some of the earlier attacks used Cobalt Strike to stage and execute the cryptominer payloads, the largest wave of attacks that began in mid-January 2022, executed the cryptominer installer script directly from the Apache Tomcat component of the VMware Horizon server. This wave of attacks is ongoing.

“Sophos’ findings suggest that multiple adversaries are implementing these attacks, so the most important protective step is to upgrade all devices and applications that include Log4J with the patched version of the software. This includes patched versions of VMware Horizon if organizations use the application in their network,” said Gallagher. “Log4J is installed in hundreds of software products and many organizations may be unaware of the vulnerability lurking within their infrastructure, particularly in commercial, open-source or custom software that doesn’t have regular security support. And while patching is vital, it won’t be enough if attackers have already been able to install a web shell or backdoor in the network. Defense in depth and acting upon any detection of miners and other anomalous activity is critical to avoid falling victim to such attacks.”

For further information read the article “Horde of Miner Bots and Backdoors Leveraged Log4J to Attack VMware Horizon Servers” on Sophos News.

Sophos has closely monitored attack activity related to the Log4Shell vulnerability and has published a number of in depth technical and advisory reports, including  Log4Shell Hell – Anatomy of an Exploit Outbreak, Log4Shell Response and Mitigation Recommendations, Inside the Code: How the Log4Shell Exploit Works, and Log4Shell: No Mass Abuse, But No Respite, What Happened?

GrassRoots.ng is on a critical mission; to objectively and honestly represent the voice of ‘grassrooters’ in International, Federal, State and Local Government fora; heralding the achievements of political and other leaders and investors alike, without discrimination. This daily, digital news publication platform serves as the leading source of up-to-date information on how people and events reflect on the global community. The pragmatic articles reflect on the life of the community people, covering news/current affairs, business, technology, culture and fashion, entertainment, sports, State, National and International issues that directly impact the locals.

Continue Reading

GRTech

Glo reduces international call rates 

By Sandra Ani

Published

on

Glo and Globacom


Technology Company, Globacom, has announced significant reductions in its International Direct Dialing (IDD) rates, making international calls more affordable for its existing and new customers across Nigeria.

Effective August 10, the new rates began applying to over 15 popular international destinations, including United States which will has moved to ₦30 per minute, down from ₦35, United Kingdom is now N350 from ₦400, while India also moved down to ₦40 from N45.

The rates for China, Saudi Arabia and Cameroon however recorded major reduction moving to N75, N300 and ₦700 respectively.


The reduction was also extended to African countries including Benin Republic which goes for ₦650 per minute, Niger Republic ₦750, Ghana ₦500, and Togo ₦650. United Arab Emirates also moved from ₦450 to ₦325, Germany to ₦550, Côte d’Ivoire ₦700, Libya ₦700, while calls to Malawi is now N1,100 from ₦1,200.

Glo aims to provide more value for its customers through these revised rates, encouraging them to make Glo their preferred network for international calls. New IDD bundles will also be introduced, offering frequent international callers even more attractive deals.

Globacom, which remained optimistic that frequent international callers will benefit immensely from the reductions in IDD bundles, enjoined customers to take advantage of the new rates to stay connected with friends and business associates across the globe.

Continue Reading

GRTech

Oil subsidy removal freed up resources for infrastructure – Enugu Governor 

By Orji Israel, South East Correspondent

Published

on

Oil benchmark

The Executive Governor of Enugu State, Peter Mbah, has attributed the financing of numerous infrastructure projects embarked by the state government to the oil subsidy removal policy of the President Bola Ahmed Tinubu administration.

He made this declaration at the Govermment House, Enugu, during a courtesy visit by a delegation of federal government led by Minister of Information and National Orientation, Mohammed Idris, as part of activities lined up for the 2-day Citizens’ Engagement Series in the South East geo-political zone.

“For us in Enugu, we are able to accomplish all we promised our people during the campaign, thanks to the bold decision taken by President Bola Tinubu, which has freed up resources needed to execute humongous capital projects,” said Governor, while listing ongoing projects in the state, which include the construction of 7,000 classrooms, 3,300 hospital beds and 2,000-hectare of 260 farm estates across the 260 wards of the state.

Governor Mbah also pledged more support for the policies of the federal government, saying they are in the best interest of the people of the state.

Continue Reading

TechNews

Samsung Launches Vision AI TV: A New Era in Home Entertainment, Celebrating 19 Consecutive Years as the Global No. 1 TV Brand

Published

on

Samsung Launches Vision AI TV
L-r: Ikechukwu Ijeh, Head of Retail, Samsund Consumer Electronics; Jingak Chung, CE Product Manager, Samsung Electronics West Africa; Oge Maduagwu, Head of Marketing Communications Samsung Electronics West Africa; Tae Sun Lee, CEO Samsung Electronics West Africa; Harris Kwak, Business Manager Samsung Electronics West Africa; Ajay David, Head Consumer electronics ,Samsung West Africa, and Adekunle Adewale, Management Strategy, Samsung Consumer Electronics, Samsung West Africa, at the launch of Samsung Vision AI TV in Lagos

Samsung Electronics has announced the launch of its groundbreaking Samsung Vision AI TV, marking a bold new chapter in the company’s history of innovation and leadership in the television industry.

For 19 consecutive years, Samsung has held the position of the world’s No. 1 TV brand, a testament to its unwavering commitment to quality, design, and user experience. This remarkable journey of excellence has been defined by a series of world first innovations that have consistently set new standards in the industry.

From the debut of the Bordeaux LCD TV in 2006, admired for the world’s first sensuous design, to other breakthroughs like the first edge type LED TV, the first Smart TV with applications, the brilliance of 100% Color Volume QLED technology, and the refined Curved UHD TV, Samsung has never stopped setting new standards for what a TV can achieve.

Now in 2025, the company has taken another bold step forward with Samsung Vision AI which positions Samsung TVs as more than entertainment devices. They enhance content interaction, smart home functionality and synergy across devices, while maintaining strong privacy with the Samsung Knox security.

“Our mission has always been to create technology that feels personal, intuitive, and inspiring,” said Tae Sun Lee, CEO of Samsung Electronics West Africa. “With Vision AI, we’re not just offering a TV, we’re introducing a smarter, more connected way to live, building on almost two decades of global leadership.”

Samsung Vision AI is packed with features designed to make the TV experience smarter and more personal:

•            Click to Search – Find information and personalized content recommendations about what you’re watching instantly, with just one click.

•            Future-Proof Design – Enjoy 7 years of free OS updates so that your TV keeps evolving, unlocking new AI-powered experiences over time.

•            Smart Home Control Tower – Effortlessly connect and control your Galaxy devices, Bespoke appliances, and other IoT products through SmartThings.

•            Knox Security – Advanced protection to keep your personal information safe while you stay connected.

•            Art & Entertainment – Seamlessly integrates with the Samsung Art TV lineup and offers immersive gaming, making it a hub for both creativity and play.

According to Oge Maduagwu, Head of Marketing & Communications, Samsung Electronics West Africa, “These new TVs are intelligent lifestyle hubs as they leverage Vision AI to deliver personalized, contextual, and seamless experiences that redefine television. Combining TV, AI Art, Live translations and sleek designs to set our TVs miles ahead of others”.

Continuing she said:

“Samsung’s 2025 TV lineup delivers our most advanced viewing experience yet, with innovations across OLED, Neo QLED, QLED, and lifestyle models. This year, we’ve introduced glare-free OLED and expanded anti-glare technology to more Neo QLED models, boosted brightness by up to 30%, and added high refresh rates up to 240Hz for ultra-smooth motion. Our new Vision AI enhances picture, sound, and even integrates smart home features like pet and family care monitoring.

“We’ve launched premium additions such as Neo QLED Mini-LED with  wireless One Connect, plus Nigeria’s first 100-inch Neo QLED. From breathtaking picture quality to intelligent home integration, 2025 Samsung TVs are designed to deliver unmatched clarity, style, and connectivity.”

She reiterated Samsung’s commitment to shaping the viewing experience of tomorrow, with innovations designed to bring joy, connection, and inspiration to households worldwide.

“For years, customers have put their trust in Samsung TVs, trusting them to get quality and value for their money, thus, making them the global No.1 TV brand for 19 years consecutively and the brand continues to honor that trust by delivering products that exceed expectations.

“The new Neo QLED 8K, OLED, Neo QLED 4K, QLED & Crystal UHD TVs are now available at all authorized Samsung stores nationwide”, she Maduagwu added.

Continue Reading

Trending