Executive Summary
In December 2025, security researchers observed a sophisticated multi-vector attack campaign, dubbed 'Sha1-Hulud,' targeting organizations across North America, Europe, and Asia. The campaign leveraged vulnerabilities in remote management tools such as ScreenConnect and MacSync to gain initial access, then proceeded laterally using encrypted traffic, zero trust segmentation evasion, and cloud-native pivoting. Attackers deployed covert remote access tools and exploited gaps in cloud firewall and egress controls to move data out, leaving organizations grappling with data theft, systems downtime, and regulatory exposure.
This incident is notable for its integration of advanced encryption bypass, multicloud movement, and the blending of traditional and cloud-native evasion tactics. The convergence of infrastructure and cloud threats highlights the need for ubiquitous visibility, modern segmentation, and coordinated policy enforcement in response to increasingly diverse and distributed attacks.
Why This Matters Now
Sha1-Hulud demonstrates how attackers are rapidly evolving to exploit both legacy and modern infrastructure, combining remote management misuse with encrypted lateral movement and cloud-native pivots. The campaign underscores urgent gaps in east-west visibility, zero trust controls, and anomaly response, making robust multi-vector defenses critical for organizations facing hybrid-cloud threats today.
Attack Path Analysis
The attacker began by exploiting exposed remote access tooling and cloud misconfigurations to gain an initial foothold. They quickly escalated privileges by abusing compromised credentials and escalating roles within the cloud environment. Lateral movement was achieved via east-west traffic, leveraging workload-to-workload communications and service identity weaknesses to pivot between segments and clusters. Secure channels were established for command and control, often utilizing encrypted outbound traffic to evade detection. Sensitive data was then exfiltrated using covert egress channels and unfiltered outbound connections. Finally, the attacker executed impactful actions such as deploying ransomware and disabling backups, causing operational disruption.
Kill Chain Progression
Initial Compromise
Description
Adversaries exploited exposed interfaces like ScreenConnect and MacSync or misconfigured cloud assets, possibly leveraging social engineering or phishing to obtain credentials.
Related CVEs
CVE-2025-3935
CVSS 8.1A ViewState code injection vulnerability in ConnectWise ScreenConnect versions 25.2.3 and earlier allows remote code execution if machine keys are compromised.
Affected Products:
ConnectWise ScreenConnect – <= 25.2.3
Exploit Status:
exploited in the wildCVE-2024-1709
CVSS 10An authentication bypass vulnerability in ConnectWise ScreenConnect versions prior to 23.9.8 allows unauthorized access to the system.
Affected Products:
ConnectWise ScreenConnect – < 23.9.8
Exploit Status:
exploited in the wildCVE-2024-1708
CVSS 9.8A path traversal vulnerability in ConnectWise ScreenConnect versions prior to 23.9.8 allows unauthorized access to restricted directories.
Affected Products:
ConnectWise ScreenConnect – < 23.9.8
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploitation of Remote Services
Valid Accounts
System Services: Service Execution
Boot or Logon Autostart Execution: Registry Run Keys/Startup Folder
Command and Scripting Interpreter
Obfuscated Files or Information
Ingress Tool Transfer
Phishing: Spearphishing Attachment
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – User Identification and Authentication
Control ID: 8.2.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 6
CISA ZTMM 2.0 – Continuous Identity Assurance
Control ID: Identity Pillar: Credential and Session Risk
NIS2 Directive – Cybersecurity Risk Management and Reporting
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Multi-vector campaigns targeting encrypted traffic and east-west segmentation expose banking infrastructure to Salt Typhoon-style attacks requiring immediate zero trust implementation.
Health Care / Life Sciences
Healthcare networks face critical HIPAA compliance violations from unencrypted traffic exposure and lateral movement threats affecting patient data protection systems.
Information Technology/IT
IT infrastructure providers vulnerable to Sha1-Hulud worms and ScreenConnect exploitation requiring enhanced Kubernetes security and multicloud visibility controls.
Government Administration
Government systems critically exposed to advanced persistent threats through compromised remote access tools and inadequate segmentation of sensitive administrative networks.
Sources
- Intelligence Insights: December 2025https://redcanary.com/blog/threat-intelligence/intelligence-insights-december-2025/Verified
- ScreenConnect 25.2.4 Security Patchhttps://www.connectwise.com/company/trust/security-bulletins/screenconnect-security-patch-2025.4Verified
- ConnectWise sounds the alarm on two vulnerabilitieshttps://news.sophos.com/en-us/2024/02/21/connectwise-sounds-the-alarm-on-two-vulnerabilities/Verified
- ScreenConnect Vulnerability Added to KEV [CVE-2025-3935]https://www.censys.com/advisory/cve-2025-3935Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying Zero Trust segmentation, robust east-west traffic security, egress filtering, and inline anomaly detection would have broken multiple stages of the attack chain by containing lateral movement, preventing unauthorized data exfiltration, and enabling early detection of anomalous activity.
Control: Cloud Firewall (ACF)
Mitigation: Ingress filtering would have blocked unauthorized or suspicious access attempts.
Control: Zero Trust Segmentation
Mitigation: Identity-based least privilege would limit access scope post-compromise.
Control: East-West Traffic Security
Mitigation: Microsegmentation and traffic monitoring would restrict unauthorized movement.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound traffic filtering blocks suspicious communication patterns.
Control: Encrypted Traffic (HPE) & Egress Security
Mitigation: Monitoring and controlling encrypted egress prevents unauthorized data transfer.
Automated anomaly detection and alerting enable rapid response.
Impact at a Glance
Affected Business Functions
- Remote Access Services
- IT Support Operations
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of sensitive client data and internal IT infrastructure details due to unauthorized remote access.
Recommended Actions
Key Takeaways & Next Steps
- • Implement cloud-native zero trust segmentation and least privilege access to minimize blast radius for compromised accounts.
- • Enforce comprehensive east-west traffic controls and microsegmentation—including Kubernetes security—for all internal flows.
- • Deploy robust egress filtering and encrypted traffic inspection to prevent unauthorized data exfiltration and external C2 communications.
- • Integrate automated threat detection and anomaly response tools capable of identifying and alerting on suspicious activity in real time.
- • Centralize multicloud policy enforcement and observability to ensure consistent governance, rapid detection, and coordinated incident response across environments.



