logo

DslogdRAT Malware Installed in Ivanti Connect Secure

ID: ca75788a-3173-5371-b4e3-efcfab79e075

STIX ID: report--ca75788a-3173-5371-b4e3-efcfab79e075

Feed Name: JPCERT Blog

Threat Score
75/100

Date Published: 2025-04-24

Date Updated: 2026-04-19

Author: 増渕 維摩(Yuma Masubuchi)

...
...

Executive Summary: This report analyzes DslogdRAT and a simple Perl web shell installed via exploitation of an Ivanti Connect Secure zero-day in attacks targeting organizations in Japan (Dec 2024), detailing malware execution flow, encoded configuration, C2 communication and commands, and providing indicators of compromise (C2 IP 3.112.192.119, file paths, and hashes); it also notes co-located SPAWNSNARE and related advisories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.