Ivanti VPN Flaws Exploited to Spread KrustyLoader Malware
ID: f3f11073-0aca-5084-9460-3b5e2e5479b7
STIX ID: report--f3f11073-0aca-5084-9460-3b5e2e5479b7
Feed Name: HackRead
Hackers exploited zero-day flaws CVE-2023-46805 and CVE-2024-21887 in Ivanti Connect Secure and Ivanti Policy Secure appliances to deploy a Rust-based loader (KrustyLoader), install Sliver backdoors and XMRig miners, and compromise over 2,100 devices across government, telecom, defense contractors, Fortune 500 companies and other sectors; the activity is attributed to Chinese actor UTA0178 (Mandiant: UNC5221), and vendors and responders were working to contain the incidents while patches were pending.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
