CARDS
CARDS
MITRE ATT&CK campaign C0039 attributes exploitation of Versa Director servers to Volt Typhoon from early June through August 2024. The campaign exploited CVE-2024-39717 at MSP and ISP management-plane servers, captured credentials, and deployed the VersaMem web shell for follow-on access. Because Versa Director can orchestrate SD-WAN environments, provider compromise creates a potential downstream client-access and service-continuity trust path.
Last updated Jul 10, 2026, 8:00 PM EDT
Actor Mapping
Targeting
Tradecraft
Tools / Observables
Source Reconciliation
Campaign rows are retained as source-backed context. Actor mappings do not automatically merge actor records; SOCRadar, MITRE, Mandiant, CrowdStrike, Microsoft, and other future sources can disagree on boundaries, aliases, or campaign ownership.
MITRE and Lumen support the campaign narrative, while NVD, CISA KEV, and Versa guidance control CVE/mitigation detail. Do not infer that every Versa Director or provider customer was compromised from KEV inclusion or campaign reporting.
IntelliOS
Citations