Active Exploitation of CVE-2026-22769

Threat Intelligence Update

In the two days several security vendors and companies have released information on CVE-2026-22769.  This is a known vulnerability in the Dell RecoverPoint for VMs.  It is being ACTIVELY exploited, and every security team should be aware of this ongoing threat.  Most reports seem to point to Chinese threat actors being involved, which means that nearly any industry vector can be a target.

Below are some Indicators of Compromise from the Google threat report.

File Indicators

FamilyFile NameSHA256
GRIMBOLT support24a11a26a2586f4fba7bfe89df2e21a0809ad85069e442da98c37c4add369a0c
GRIMBOLTout_elf_2dfb37247d12351ef9708cb6631ce2d7017897503657c6b882a711c0da8a9a591
SLAYSTYLEdefault_jsp.java92fb4ad6dee9362d0596fda7bbcfe1ba353f812ea801d1870e37bfc6376e624a
BRICKSTORMN/Aaa688682d44f0c6b0ed7f30b981a609100107f2d414a3a6e5808671b112d1878
BRICKSTORMsplisten2388ed7aee0b6b392778e8f9e98871c06499f476c9e7eae6ca0916f827fe65df
BRICKSTORMN/A320a0b5d4900697e125cebb5ff03dee7368f8f087db1c1570b0b62f5a986d759
BRICKSTORMN/A90b760ed1d0dcb3ef0f2b6d6195c9d852bcb65eca293578982a8c4b64f51b035
BRICKSTORMN/A45313a6745803a7f57ff35f5397fdf117eaec008a76417e6e2ac8a6280f7d830

Network Indicators

FamilyIndicatorType
GRIMBOLTwss://149.248.11.71/rest/apisessionC2 Endpoint
GRIMBOLT149.248.11.71C2 IP

As an aside I did a bit of research on my own and found that the first hash presented doesn’t show up in Virus Total as malicious!

It is important to note that many EDR/MDR, AV and other products should be updated immediately with these IOCs in order to protect your network.  Especially if you are utilizing the affected tools and programs.

The second hash shows the same type of results.  There are comments on Virus Total identifying this tool as malicious and referencing the associated reports, but as of the current time many of your security tools will not identify or alert on this particular piece of malware. 

The same is true of the IP address provided in the threat reports.  See below:

Only one vendor at this point is identifying this IP as malicious.  So, take heed security practitioners and update your tools proactively with the intelligence contained in the below listed reports ASAP.

Sources:  https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day

Leave a Reply

Discover more from Dave Does Cyber Security

Subscribe now to keep reading and get access to the full archive.

Continue reading