logo

Ivanti Zero-Day Patches Delayed as 'KrustyLoader' Attacks Mount

ID: 62105d49-95a6-58fa-a225-fa9bc8a9dfdc

STIX ID: report--62105d49-95a6-58fa-a225-fa9bc8a9dfdc

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-01-30

Date Updated: 2026-04-21

Author: Tara Seals, Managing Editor, News, Dark Reading

...
...

### Executive Summary Attackers are actively exploiting two Ivanti Connect Secure VPN zero-days (CVE-2024-21887 and CVE-2023-46805) to deploy Rust-based backdoors that fetch a Sliver-derived implant dubbed "KrustyLoader." The activity — attributed to Chinese state-linked actor UNC5221 (UTA0178) — involves mass exploitation worldwide, includes IoCs and detection scripts, and is compounded by delayed patches from Ivanti.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.