Ivanti Zero-Day Patches Delayed as 'KrustyLoader' Attacks Mount
ID: 62105d49-95a6-58fa-a225-fa9bc8a9dfdc
STIX ID: report--62105d49-95a6-58fa-a225-fa9bc8a9dfdc
Feed Name: Dark Reading
Date Published: 2024-01-30
Date Updated: 2026-04-21
Author: Tara Seals, Managing Editor, News, Dark Reading
### Executive Summary Attackers are actively exploiting two Ivanti Connect Secure VPN zero-days (CVE-2024-21887 and CVE-2023-46805) to deploy Rust-based backdoors that fetch a Sliver-derived implant dubbed "KrustyLoader." The activity — attributed to Chinese state-linked actor UNC5221 (UTA0178) — involves mass exploitation worldwide, includes IoCs and detection scripts, and is compounded by delayed patches from Ivanti.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
