Threat Intelligence Update
In the two days several security vendors and companies have released information on CVE-2026-22769. This is a known vulnerability in the Dell RecoverPoint for VMs. It is being ACTIVELY exploited, and every security team should be aware of this ongoing threat. Most reports seem to point to Chinese threat actors being involved, which means that nearly any industry vector can be a target.
Below are some Indicators of Compromise from the Google threat report.
File Indicators
| Family | File Name | SHA256 |
| GRIMBOLT | support | 24a11a26a2586f4fba7bfe89df2e21a0809ad85069e442da98c37c4add369a0c |
| GRIMBOLT | out_elf_2 | dfb37247d12351ef9708cb6631ce2d7017897503657c6b882a711c0da8a9a591 |
| SLAYSTYLE | default_jsp.java | 92fb4ad6dee9362d0596fda7bbcfe1ba353f812ea801d1870e37bfc6376e624a |
| BRICKSTORM | N/A | aa688682d44f0c6b0ed7f30b981a609100107f2d414a3a6e5808671b112d1878 |
| BRICKSTORM | splisten | 2388ed7aee0b6b392778e8f9e98871c06499f476c9e7eae6ca0916f827fe65df |
| BRICKSTORM | N/A | 320a0b5d4900697e125cebb5ff03dee7368f8f087db1c1570b0b62f5a986d759 |
| BRICKSTORM | N/A | 90b760ed1d0dcb3ef0f2b6d6195c9d852bcb65eca293578982a8c4b64f51b035 |
| BRICKSTORM | N/A | 45313a6745803a7f57ff35f5397fdf117eaec008a76417e6e2ac8a6280f7d830 |
Network Indicators
| Family | Indicator | Type |
| GRIMBOLT | wss://149.248.11.71/rest/apisession | C2 Endpoint |
| GRIMBOLT | 149.248.11.71 | C2 IP |
As an aside I did a bit of research on my own and found that the first hash presented doesn’t show up in Virus Total as malicious!

It is important to note that many EDR/MDR, AV and other products should be updated immediately with these IOCs in order to protect your network. Especially if you are utilizing the affected tools and programs.
The second hash shows the same type of results. There are comments on Virus Total identifying this tool as malicious and referencing the associated reports, but as of the current time many of your security tools will not identify or alert on this particular piece of malware.
The same is true of the IP address provided in the threat reports. See below:

Only one vendor at this point is identifying this IP as malicious. So, take heed security practitioners and update your tools proactively with the intelligence contained in the below listed reports ASAP.
Leave a Reply