logo

Sleeping with the Enemy: Dormant Backdoors Found in Ivanti EPMM

ID: 8b4f2234-e0fb-5819-95df-f4f265b7af04

STIX ID: report--8b4f2234-e0fb-5819-95df-f4f265b7af04

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-02-11

Date Updated: 2026-04-23

Author: Ddos

...
...

A stealthy espionage campaign has been observed exploiting two Ivanti EPMM flaws (CVE-2026-1281 and CVE-2026-1340) to install a dormant, in-memory Java class loader at /mifs/403.jsp that does nothing until a specific trigger; researchers attribute the activity to Initial Access Brokers preparing validated access for later sale or activation. The implant leaves minimal forensic traces, so the advisory provides IoCs (requests to /mifs/403.jsp, large Base64 starting with yv66vg, parameter name k0f53cf964d387, and response markers like ERROR:// and 3cd3d/e60537) and recommends restarting affected application servers and treating any signs as confirmed compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.