logo

Ivanti Connect Secure zero-days exploited to deploy custom malware

ID: cb66c715-63a4-541f-aca0-0322899e00ae

STIX ID: report--cb66c715-63a4-541f-aca0-0322899e00ae

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2024-01-12

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Ivanti Connect Secure appliances are being actively exploited via two zero-day vulnerabilities (CVE-2023-46805 and CVE-2024-21887) by a threat actor tracked as UNC5221 to install multiple custom malware families (notably the Zipline passive backdoor, Thinspool dropper, Wirefire/Lightwire web shells, Warpwire credential harvester and PySoxy tunneler). Mandiant's analysis links these tools to post-compromise persistence, credential theft, command execution and covert tunneling, and Shadowserver reports thousands of Ivanti CS devices exposed online; Ivanti published mitigations while investigations continue and no full patch had been available at the time of reporting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.