logo

Covert TLS n-day backdoors: SparkCockpit & SparkTar

ID: 1c941505-5b9f-56eb-b14f-956f94250d54

STIX ID: report--1c941505-5b9f-56eb-b14f-956f94250d54

Feed Name: NVISO Labs

Threat Score
88/100

Date Published: 2024-03-01

Date Updated: 2026-04-28

Author: Maxime Thiebaut

...
...

NVISO identified two previously undetected, TLS-intercepting backdoors—SparkCockpit and SparkTar—on Ivanti Pulse Secure appliances exploited via CVE-2023-46805 and CVE-2024-21887; the implants provide stealthy selective TLS interception, remote command execution, file upload and SOCKS tunneling (potentially enabling full internal network access), with SparkTar exhibiting extreme persistence (surviving factory resets and upgrades).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.