logo

Chinese Hackers Deployed Backdoor Quintet to Down MITRE

ID: 23eabf78-ae88-591b-a81a-f145398581ce

STIX ID: report--23eabf78-ae88-591b-a81a-f145398581ce

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-05-07

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

MITRE disclosed that Chinese-linked attackers exploited Ivanti Connect Secure zero-day vulnerabilities to breach its NERVE research environment between New Year's Eve and mid‑March, deploying multiple web shells and backdoors — Rootrot (Ivanti TCC backdoor), Brickstorm (Golang vCenter backdoor), Wirefire/Gifted Visitor (Python web shell), Bushwalk (Perl web shell variant), and Beeflush (web shell that reads/encrypts web traffic) — enabling reconnaissance, lateral movement, command-and-control, and file operations; MITRE emphasized secure-by-design, zero trust, continuous authentication, and SBOMs as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.