Covert TLS n-day backdoors: SparkCockpit & SparkTar
ID: 1c941505-5b9f-56eb-b14f-956f94250d54
STIX ID: report--1c941505-5b9f-56eb-b14f-956f94250d54
Feed Name: NVISO Labs
Threat Score
NVISO identified two previously undetected, TLS-intercepting backdoors—SparkCockpit and SparkTar—on Ivanti Pulse Secure appliances exploited via CVE-2023-46805 and CVE-2024-21887; the implants provide stealthy selective TLS interception, remote command execution, file upload and SOCKS tunneling (potentially enabling full internal network access), with SparkTar exhibiting extreme persistence (surviving factory resets and upgrades).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
