Ivanti Connect Secure zero-days exploited to deploy custom malware
ID: cb66c715-63a4-541f-aca0-0322899e00ae
STIX ID: report--cb66c715-63a4-541f-aca0-0322899e00ae
Feed Name: Bleeping Computer
Ivanti Connect Secure appliances are being actively exploited via two zero-day vulnerabilities (CVE-2023-46805 and CVE-2024-21887) by a threat actor tracked as UNC5221 to install multiple custom malware families (notably the Zipline passive backdoor, Thinspool dropper, Wirefire/Lightwire web shells, Warpwire credential harvester and PySoxy tunneler). Mandiant's analysis links these tools to post-compromise persistence, credential theft, command execution and covert tunneling, and Shadowserver reports thousands of Ivanti CS devices exposed online; Ivanti published mitigations while investigations continue and no full patch had been available at the time of reporting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
