logo

Malicious Listeners in Ivanti EPMM: How CVE-2025-4427 and CVE-2025-4428 Created Backdoors

ID: b50013ae-0dba-5167-9195-d832ab656d69

STIX ID: report--b50013ae-0dba-5167-9195-d832ab656d69

Feed Name: Resources-2

Threat Score
80/100

Date Published: 2025-09-19

Date Updated: 2026-07-22

Author: Huseyin Can YUCEEL

...
...

CISA analyzed active exploitation of Ivanti Endpoint Manager Mobile vulnerabilities CVE-2025-4427 (authentication bypass) and CVE-2025-4428 (code injection) where attackers dropped loader JARs and installed malicious Tomcat listeners that decode, decrypt (AES), and dynamically load Java classes in memory to run arbitrary code; the report describes two malware sets, their components, IOCs (file/class names and an embedded AES key), and advises urgent patching and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.