New Malware Variant RESURGE Exploits Ivanti Vulnerability
ID: 1f28de98-99ba-5062-b90d-3136f14fb934
STIX ID: report--1f28de98-99ba-5062-b90d-3136f14fb934
Feed Name: Infosecurity Magazine (News)
CISA has uncovered RESURGE, a sophisticated malware variant exploiting a stack-based buffer overflow (CVE-2025-0282) in Ivanti Connect Secure/Policy Secure/ZTA Gateway appliances to embed web shells, alter coreboot and kernel images for persistence, inject into legitimate processes, create SSH tunnels for C2, and evade integrity checks; the agency published YARA/SIGMA rules, recommended urgent mitigations (factory resets, credential resets, privilege restrictions), and noted links to SPAWNCHIMERA/SPAWNSLOTH tools and active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
