Security researchers report a suspected Chinese state-linked group quietly abused a critical Dell software flaw for over a year before public disclosure. The vulnerability affected RecoverPoint for Virtual Machines, a backup and recovery platform used in VMware environments.
The issue involved hardcoded credentials that allowed attackers to authenticate without authorization. With this access, intruders could reach system-level privileges and remain inside networks for extended periods.
Custom backdoor deployed
After gaining entry, the attackers installed a malware implant called Grimbolt. The tool replaced an earlier backdoor and appears optimized for speed and stealth.
The change suggests the operators actively maintain their intrusion toolkit while campaigns are ongoing, adapting when detection risks increase.
Focus on virtual infrastructure
The campaign targeted virtualization layers rather than individual endpoints. Investigators observed attackers creating hidden network interfaces on VMware ESXi servers, allowing movement across internal systems while avoiding monitoring tools.
Because backup and recovery platforms often lack strong endpoint protections, they provided a reliable foothold inside affected organizations. From there, attackers could access connected systems and cloud services.
Links to espionage activity
Technical overlaps connect the activity to known Chinese intrusion clusters that historically focus on long-term intelligence collection. The behavior indicates persistence and data access were the primary objectives rather than immediate disruption or financial gain.
Mitigation steps
Dell released security updates addressing the vulnerability and advises customers to patch affected versions immediately. Since authentication relied on embedded credentials, unpatched systems remain exposed until updated.
Conclusion
The Dell intrusion highlights the value attackers place on infrastructure software that manages backups and virtual machines. Compromising these systems can provide broad visibility across entire environments. The case underscores the importance of rapid patching for centralized management platforms that hold privileged access within enterprise networks.


0 responses to “Dell zero-day attacks enabled long-term network access”