logo

Hackers Exploiting Ivanti EPMM Devices to Deploy Dormant Backdoors

ID: 4bd62323-ab8c-5f9e-8b0f-f2a8d9e0a3c9

STIX ID: report--4bd62323-ab8c-5f9e-8b0f-f2a8d9e0a3c9

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-02-09

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Ivanti EPMM appliances are being actively exploited in the wild to install a dormant, in-memory Java class loader at /mifs/403.jsp (class base.Info) via unauthenticated flaws (CVE-2026-1281 and CVE-2026-1340); the loader awaits a second-stage Base64-encoded class delivered via the HTTP parameter k0f53cf964d387, avoids disk writes, and returns responses wrapped in delimiters (3cd3d / e60537). The report includes detection and mitigation guidance (patch and restart application servers), a SHA-256 for the implant, request/response patterns to hunt for, and a list of observed source IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.