logo

CISA warns that RESURGE malware can be dormant on Ivanti devices

ID: 05972ff4-f345-5d82-9e11-7adf9e310791

STIX ID: report--05972ff4-f345-5d82-9e11-7adf9e310791

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-02-27

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

CISA published an updated analysis of RESURGE, a sophisticated 32-bit Linux implant (libdsupgrade.so) used in zero-day attacks exploiting CVE-2025-0282 against Ivanti Connect Secure devices. RESURGE uses kernel- and boot-level persistence, hooks accept() to wait for a specially fingerprinted inbound TLS connection (using CRC32 TLS fingerprinting and a forged Ivanti certificate) to avoid network detection, establishes mutual EC-TLS for remote access, and includes components for log tampering and firmware manipulation; CISA links active exploitation to a China-associated actor (UNC5221) and provides IoCs for discovery and removal.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.