CISA Warns RESURGE Malware Can Remain Dormant on Ivanti Connect Secure Devices
ID: ae334d68-59d9-542e-af74-176b152bfea5
STIX ID: report--ae334d68-59d9-542e-af74-176b152bfea5
Feed Name: The Cyber Express
CISA's updated analysis of RESURGE malware reports that attackers exploit Ivanti Connect Secure (CVE-2025-0282) to install highly stealthy, dormant implants that use advanced encryption (ECC), forged TLS certificates, SSH tunnels, TLS fingerprinting, CRC32 hashing, file manipulation and web shells to maintain covert command-and-control; the update emphasizes the difficulty of detection and removal and urges organizations to apply patches, perform threat hunting, and deploy updated IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
