{"id":10812,"date":"2026-02-20T10:03:45","date_gmt":"2026-02-20T10:03:45","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/20\/hackers-actively-exploiting-critical-beyondtrust-vulnerability-to-deploy-vshell-and-sparkrat\/"},"modified":"2026-02-20T10:03:45","modified_gmt":"2026-02-20T10:03:45","slug":"hackers-actively-exploiting-critical-beyondtrust-vulnerability-to-deploy-vshell-and-sparkrat","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/20\/hackers-actively-exploiting-critical-beyondtrust-vulnerability-to-deploy-vshell-and-sparkrat\/","title":{"rendered":"Hackers Actively Exploiting Critical BeyondTrust Vulnerability to Deploy VShell and SparkRAT"},"content":{"rendered":"<p>    Hackers Actively Exploiting Critical BeyondTrust Vulnerability to Deploy VShell and SparkRAT<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical vulnerability in BeyondTrust\u2019s remote support software is being actively exploited by hackers to deliver dangerous backdoors on compromised systems. <\/p>\n<p>The flaw, tracked as CVE-2026-1731, carries a CVSS score of 9.9 and lets attackers run system commands with no login required.<\/p>\n<p>BeyondTrust released a security advisory on February 6, 2026, confirming that CVE-2026-1731 is an OS command injection vulnerability (CWE-78) in the\u00a0<code>thin-scc-wrapper<\/code>\u00a0component, which is exposed directly to the network via WebSocket. <\/p>\n<p>Sectors targeted by this campaign include financial services, healthcare, legal services, higher education, and technology firms across the United States, France, Germany, Australia, and Canada.<\/p>\n<p><a href=\"https:\/\/unit42.paloaltonetworks.com\/beyondtrust-cve-2026-1731\/?utm_campaign=cybersecuritynews\" id=\"https:\/\/unit42.paloaltonetworks.com\/beyondtrust-cve-2026-1731\/?utm_campaign=cybersecuritynews\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Palo Alto Networks\u2019 Unit 42 analysts identified active exploitation<\/a> across more than 10,600 exposed instances, tracking a broad campaign that rapidly escalates from initial access to full control. <\/p>\n<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-1731 to its Known Exploited Vulnerabilities (KEV) Catalog on February 13, 2026, mandating urgent remediation for federal agencies and urging private-sector organizations to act immediately.<\/p>\n<p>Two backdoors sit at the core of this campaign. <a href=\"https:\/\/cybersecuritynews.com\/hackers-using-sparkrat-in-wild\/\" id=\"90437\" target=\"_blank\" rel=\"noreferrer noopener\">SparkRAT is an open-source<\/a>, Go-based remote access Trojan first seen in 2023 in campaigns linked to the DragonSpark threat group. <\/p>\n<p>VShell is a Linux backdoor known for fileless memory execution and its ability to blend in as a normal system service, making it hard to detect.<\/p>\n<p>CVE-2026-1731 connects historically to CVE-2024-12356, an earlier BeyondTrust flaw exploited by <a href=\"https:\/\/cybersecuritynews.com\/microsoft-warns-of-silk-typhoon-hackers\/\" id=\"94858\" target=\"_blank\" rel=\"noreferrer noopener\">Silk Typhoon<\/a> (APT27) in the 2024 breach of the U.S. Treasury. <\/p>\n<p>The same recurring weakness \u2014 insufficient input validation \u2014 shows up in both vulnerabilities, signaling that remote access platforms remain a prime target for sophisticated threat actors.<\/p>\n<h2 class=\"wp-block-heading\" id=\"inside-the-infection-chain\"><strong>Inside the Infection Chain<\/strong><\/h2>\n<p>The attack starts when a threat actor opens a WebSocket connection to the appliance and submits a malformed\u00a0<code>remoteVersion<\/code>\u00a0value formatted as\u00a0<code>a[$(cmd)]0<\/code>\u00a0during the handshake phase.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi0FiQjPo_Rf-DstO2QJzYGlS3pgM8tDpLAKRC_e0fKM6c-gQkd1XhAH6dfEcSZRTBCx-OS6xCRERFiHBKyGQhdzRZD3_Fv3ytWYWgNe2VQ938jtMHQvsgkgvvuQ4uyzOkfD1JSHCzBtB_3zDApF7tolO_m5s7IPh7cPUB5dGUfx3EuMjNHZ-pGYyVhMIQ\/s16000\/Custom%2520Python%2520script%2520for%2520administrative%2520account%2520access%2520%28Source%2520-%2520Palo%2520Alto%2520Networks%29.webp?ssl=1\" alt=\"Custom Python script for administrative account access (Source - Palo Alto Networks)\"><figcaption class=\"wp-element-caption\">Custom Python script for administrative account access (Source \u2013 Palo Alto Networks)<\/figcaption><\/figure>\n<\/div>\n<p>The\u00a0<code>thin-scc-wrapper<\/code>\u00a0script processes this value using bash arithmetic contexts, which treat the input as runnable expressions rather than plain numbers \u2014 causing the injected command to execute silently.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhoO2_1glCFKlTzS4EJ-wGgtCCHwfVU1ZHHb6u0LWsrevJh8OK52JKgagSo36T40-MPlDMHZAwPXI8Tt5O-KfQDRXKDxiiYlGiBzaChU6ljkafxvt4PM2Ufr_4IEgzXTxrRMDTdqB7zmUbB1L7Nsf1y1HmNvgbabKZJxgYZIj4ZdzUSJKpIB6wU5VgIRuE\/s16000\/One-line%2520PHP%2520web%2520shell%2520seen%2520in%2520activity%2520exploiting%2520CVE-2026-1731%2520%28Source%2520-%2520Palo%2520Alto%2520Networks%29.webp?ssl=1\" alt=\"One-line PHP web shell seen in activity exploiting CVE-2026-1731 (Source - Palo Alto Networks)\"><figcaption class=\"wp-element-caption\">One-line PHP web shell seen in activity exploiting CVE-2026-1731 (Source \u2013 Palo Alto Networks)<\/figcaption><\/figure>\n<\/div>\n<p>Attackers follow this with web shell deployment, installing a compact <a href=\"https:\/\/cybersecuritynews.com\/hackers-exploit-php-vulnerability-in-windows\/\" id=\"75354\" target=\"_blank\" rel=\"noreferrer noopener\">PHP backdoor<\/a> via the\u00a0<code>eval()<\/code>\u00a0function and a multi-vector shell named\u00a0<code>aws.php<\/code>.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjaQvr8nj_4A233DkPIgOPqHDSyAlPf4vn9o2tpZ3ScdImoZTkwymCbb9bLq9mDvskjobQ7jnRzxbS-guucASvFHJwkjUbDhPOfiquWe6CVpuFqiYysvvHeselO9u4K09bqa-QqhyWObW6qMnH706i5fz832alQSxd_vEm6OvfCKdmm_-LvvefFhlNReIA\/s16000\/PHP%2520web%2520shell%2520aws.php%2520%28Source%2520-%2520Palo%2520Alto%2520Networks%29.webp?ssl=1\" alt=\"PHP web shell aws.php (Source - Palo Alto Networks)\"><figcaption class=\"wp-element-caption\">PHP web shell aws.php (Source \u2013 Palo Alto Networks)<\/figcaption><\/figure>\n<\/div>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">CVE ID<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">CVSS Score<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Severity<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Type<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">CVE-2026-1731\u200b<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">9.9<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Critical<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">OS Command Injection (CWE-78)<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Pre-authentication RCE in <code>thin-scc-wrapper<\/code> component of BeyondTrust Remote Support and PRA via malformed WebSocket <code>remoteVersion<\/code> input<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">CVE-2024-12356<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Critical<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Critical<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Input Validation Failure<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Earlier BeyondTrust WebSocket endpoint flaw exploited by Silk Typhoon (APT27); predecessor to CVE-2026-1731<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>A bash dropper then plants a password-protected backdoor in the web root, temporarily injects a malicious Apache configuration directive, and immediately overwrites the config file on disk to hide all evidence.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEixAkCjsEX_icyIfP3RyNPk0gm8KJLxJgAtMGwf5HapD2So4yRNVAhCSBc1zB0lJVr10zyf4S2UQXhIGdflJivvSHcCHgiCBbvU0Jr9zAAU6H0uks0SW0q1Piq-FgxKIBNzutiJ-Om6QdGOteA4kiamQnwSzOZjriTdFYdy5j3rAb0jJuW5-vRjaXShSnc\/s16000\/Bash%2520dropper%2520seen%2520in%2520the%2520attacks%2520%28Source%2520-%2520Palo%2520Alto%2520Networks%29.webp?ssl=1\" alt=\"Bash dropper seen in the attacks (Source - Palo Alto Networks) \"><figcaption class=\"wp-element-caption\">Bash dropper seen in the attacks (Source \u2013 Palo Alto Networks) <\/figcaption><\/figure>\n<\/div>\n<p>BeyondTrust advises self-hosted customers to manually apply available patches \u2014 Remote Support 25.3.2 and Privileged <a href=\"https:\/\/cybersecuritynews.com\/enterprise-remote-access-software\/\" id=\"29330\" target=\"_blank\" rel=\"noreferrer noopener\">Remote Access<\/a> 25.1.1 \u2014 and to upgrade older versions below 21.3 (RS) or 22.1 (PRA) before patching.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hackers-actively-exploiting-critical-beyondtrust-vulnerability\/\">Hackers Actively Exploiting Critical BeyondTrust Vulnerability to Deploy VShell and SparkRAT<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hackers-actively-exploiting-critical-beyondtrust-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Actively Exploiting Critical BeyondTrust Vulnerability to Deploy VShell and SparkRAT A critical vulnerability in BeyondTrust\u2019s remote support software is being actively exploited by hackers to deliver dangerous backdoors on compromised systems. The flaw, tracked as CVE-2026-1731, carries a CVSS score of 9.9 and lets attackers run system commands with no login required. BeyondTrust released [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-10812","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10812"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10812"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10812\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10812"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10812"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10812"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}