Malicious Listeners in Ivanti EPMM: How CVE-2025-4427 and CVE-2025-4428 Created Backdoors
ID: b50013ae-0dba-5167-9195-d832ab656d69
STIX ID: report--b50013ae-0dba-5167-9195-d832ab656d69
Feed Name: Resources-2
Threat Score
CISA analyzed active exploitation of Ivanti Endpoint Manager Mobile vulnerabilities CVE-2025-4427 (authentication bypass) and CVE-2025-4428 (code injection) where attackers dropped loader JARs and installed malicious Tomcat listeners that decode, decrypt (AES), and dynamically load Java classes in memory to run arbitrary code; the report describes two malware sets, their components, IOCs (file/class names and an embedded AES key), and advises urgent patching and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
