Hackers Exploiting Vulnerabilities in Ivanti Connect Secure to Deploy MetaRAT Malware
ID: 2efc98d6-b791-57d8-8c07-5e27f9229f86
STIX ID: report--2efc98d6-b791-57d8-8c07-5e27f9229f86
Feed Name: cybersecurityNews.com
A China-linked APT campaign (discovered April 2025) exploited two critical Ivanti Connect Secure vulnerabilities (CVE-2024-21893 and CVE-2024-21887) against Japanese shipping and transportation firms to install PlugX-family RATs, including newly documented MetaRAT and Talisman PlugX. The attackers used DLL side‑loading, multi-layer encryption/compression, API hashing and anti-debugging, performed reconnaissance and credential harvesting, and moved laterally using Active Directory privileged accounts; indicators include ERR31093 logs, suspicious files (LITTLELAMB, WOOLTEA, PITSOCK, PITFUEL), service/registry names (e.g., "sihosts", "matesile") and keylog files (VniFile.hlp).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
