CISA warns that RESURGE malware can be dormant on Ivanti devices
ID: 05972ff4-f345-5d82-9e11-7adf9e310791
STIX ID: report--05972ff4-f345-5d82-9e11-7adf9e310791
Feed Name: Bleeping Computer
CISA published an updated analysis of RESURGE, a sophisticated 32-bit Linux implant (libdsupgrade.so) used in zero-day attacks exploiting CVE-2025-0282 against Ivanti Connect Secure devices. RESURGE uses kernel- and boot-level persistence, hooks accept() to wait for a specially fingerprinted inbound TLS connection (using CRC32 TLS fingerprinting and a forged Ivanti certificate) to avoid network detection, establishes mutual EC-TLS for remote access, and includes components for log tampering and firmware manipulation; CISA links active exploitation to a China-associated actor (UNC5221) and provides IoCs for discovery and removal.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
