logo

CISA Warns of Resurge Malware Connected to Ivanti Vuln

ID: 121dd909-8711-51fc-8512-cfd3a864bae9

STIX ID: report--121dd909-8711-51fc-8512-cfd3a864bae9

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2025-03-31

Date Updated: 2026-04-21

Author: Kristina Beek, Associate Editor, Dark Reading

...
...

CISA warns that threat actors are exploiting a critical Ivanti Connect Secure vulnerability (CVE-2025-0282) with malware dubbed "Resurge," which creates an SSH tunnel for command-and-control, deploys a web shell on the Ivanti boot disk, modifies files and integrity checks, and is used to harvest credentials, create accounts, and escalate privileges; CISA observed additional binaries (a SpawnSloth variant and a BusyBox-based embedded binary) and recommends factory resets, credential resets, access policy reviews, monitoring, and Ivanti recovery steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.