logo

CISA Details New Malware Used in Ivanti Attacks

ID: 0459151e-4a5d-590e-81f2-47e2a5a809ac

STIX ID: report--0459151e-4a5d-590e-81f2-47e2a5a809ac

Feed Name: The Cyber Express

Threat Score
85/100

Date Published: 2025-03-31

Date Updated: 2026-04-23

Author: Paul Shread

...
...

CISA published an advisory on exploitation of Ivanti Connect Secure CVE-2025-0282 in a critical infrastructure environment where analysts recovered three malicious files, including a new 32-bit Linux shared object named RESURGE (libdsupgrade.so) that implements a rootkit, dropper, backdoor, bootkit, proxy/tunneler, modifies files and integrity checks, and installs a web shell; CISA provided file hashes, YARA rules, and mitigation recommendations such as disabling unnecessary services, enforcing strong authentication, using host firewalls, and scanning for suspicious attachments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.