IntelliOS Threat Intel Operating System
IntelliOSPANDAModule|AIFlash Threat Intel Brief

Versa Director Zero Day Exploitation

Volt Typhoon Campaign, CVE-2024-39717, and MSP/ISP Trust-Path Risk

CVE-2024-39717CISA KEVMSP / ISP control plane
Published
Jul 11, 2026
Brief Version
v1.1
Updated
Jul 18, 2026
Next AI Monitor
Daily at 1:00 PM ET for 12 months
Brief ID
PANDA-FTIB-VERSA-VOLT-2026-001
Template
Flash Threat Brief v2.0

Research Framing

Campaign Snapshot

1-Topic

This brief covers MITRE ATT&CK campaign C0039: Volt Typhoon's exploitation of Versa Director servers from June through August 2024. The campaign used CVE-2024-39717 against a high-value SD-WAN management plane, with the public record describing credential capture, VersaMem web-shell activity, and risk to ISP and MSP client relationships.1, 2, 3

2-Persona / Audience Lens

3-BLUF

  • This was a targeted control-plane intrusion campaign, not indiscriminate mass exploitation: Black Lotus Labs identified five observed victims in ISP, MSP, and IT sectors. The small research set does not reduce the consequence: a compromised Director can expose provider credentials and trusted paths into managed customer networks.1, 2
  • The exploit conditions matter as much as the CVE number: The CVE record describes a dangerous file upload available to specific privileged provider administrators. Versa and Black Lotus Labs report that missing firewall and hardening controls exposed a management path used for initial access in observed cases.2, 3, 4
  • CVE-2024-39717 is a KEV and requires verified remediation: CISA added the vulnerability to KEV on August 23, 2024. Verify the exact Director image and June 21 hot-fix boundary, apply current vendor hardening, and restrict high-availability management ports to approved Director peers.3, 4, 5
  • VersaMem makes a clean file scan insufficient: The custom JAR web shell attached to Tomcat, modified Java behavior in memory, intercepted plaintext credentials, and could load additional code without leaving ordinary Java files behind. Hunt process memory, authentication, temporary files, accounts, and network behavior—not only one filename.1, 2
  • Patching does not answer whether credentials or clients were reached: After remediation, determine which users authenticated to the affected Director, whether credentials were captured or reused, and which customer tenants or network-control paths those credentials could access.1, 2, 4
  • Keep attribution and downstream impact evidence-bound: MITRE associates C0039 with Volt Typhoon, while Black Lotus Labs assessed the actor link with moderate confidence. Neither campaign attribution nor provider compromise alone proves that a specific downstream customer was accessed.1, 2, 6

4-Executive Summary

MITRE ATT&CK tracks C0039 as a June-through-August 2024 Volt Typhoon campaign against Versa Director systems used by MSPs and ISPs. Black Lotus Labs identified four U.S. and one non-U.S. observed victim and assessed the activity as targeted, with the earliest observed U.S. exploitation on June 12.1, 2

The public vulnerability and campaign records must be read together. NVD describes a dangerous favicon-upload function available after a specific privileged provider-administrator login. Versa and Black Lotus Labs add the campaign condition: missing firewall and system-hardening controls left a high-availability management port exposed, enabling the observed initial-access path.2, 3, 4

After access, the actor deployed VersaMem, a custom JAR web shell designed for Versa Director. It attached to the Tomcat Java process, changed application behavior in memory, intercepted plaintext credentials, stored encrypted results in /tmp/.temp.data, and supported additional in-memory Java modules. This design reduces the value of file-only detection and raises the importance of credential and downstream-session review.1, 2

The response therefore has two tracks: verify the exact fixed release and hardening state, then establish historical compromise and provider-to-client impact. The decision-ready output is an instance-level exposure record, a preserved compromise timeline, an affected-credential list, and a client-by-client reachability and evidence matrix.1, 2, 3, 4, 5

MITRE records the campaign-to-Volt Typhoon relationship; Black Lotus Labs expressed moderate confidence in the attribution. Microsoft and the CISA-led joint advisory supply broader actor context, but their wider critical-infrastructure reporting is not automatic proof of behavior, targeting, or impact in any particular Versa Director incident.1, 2, 6, 7, 8

5-AI Agent Delta Updates

6-Why It Matters

7-Timeline

8-Incident Response Playbook Ideas

9-Term Glossary

10-TTPs

11-Common Questions Q&A

12-CVE / Vulnerability References

13-IOCs / Observables

14-Threat Actor Glossary

15-Talking Points

16-Decision Ready Actions

17-Exploitable Technology Risks

18-Social Media / Community Signals

19-Tier 0 Through Tier 8 Source Summary

20-Source Reconciliation

21-About the Contributors

22-Real World Examples

23-Public Victims / Disclosure Matrix

24-KEV and CVE Details

25-MITRE ATT&CK Lifecycle Mapping

26-Source Weighting / Relevance

27-Additional IntelliOS Threat Intel Products on This Topic

28-Notes

29-Citations

30-Version Change Log