logo

JPCERT warns of DslogdRAT malware deployed in Ivanti Connect Secure

ID: ba7f4067-c778-5719-b981-19afb62d2455

STIX ID: report--ba7f4067-c778-5719-b981-19afb62d2455

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2025-04-25

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

JPCERT/CC reports that attackers exploited a now-patched stack-based buffer overflow (CVE-2025-0282, CVSS 9.0) in Ivanti Connect Secure to install a Perl-based CGI web shell that authenticated via a specific DSAUTOKEN cookie and was used to run a new RAT called DslogdRAT. DslogdRAT uses XOR-encoded hardcoded configuration, spawns child processes (one idle, one handling C2 via sockets with simple XOR encoding), supports proxying, file upload/download, and command execution, and is configured to operate during business hours to evade detection; SPAWNSNARE was also observed on the same hosts. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog and Microsoft tied related activity to a China-linked APT (Silk Typhoon), indicating active, high-impact exploitation against IT supply-chain targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.