JPCERT warns of DslogdRAT malware deployed in Ivanti Connect Secure
ID: ba7f4067-c778-5719-b981-19afb62d2455
STIX ID: report--ba7f4067-c778-5719-b981-19afb62d2455
Feed Name: Security Affairs
JPCERT/CC reports that attackers exploited a now-patched stack-based buffer overflow (CVE-2025-0282, CVSS 9.0) in Ivanti Connect Secure to install a Perl-based CGI web shell that authenticated via a specific DSAUTOKEN cookie and was used to run a new RAT called DslogdRAT. DslogdRAT uses XOR-encoded hardcoded configuration, spawns child processes (one idle, one handling C2 via sockets with simple XOR encoding), supports proxying, file upload/download, and command execution, and is configured to operate during business hours to evade detection; SPAWNSNARE was also observed on the same hosts. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog and Microsoft tied related activity to a China-linked APT (Silk Typhoon), indicating active, high-impact exploitation against IT supply-chain targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
