logo

CISA Warns RESURGE Malware Can Remain Dormant on Ivanti Connect Secure Devices

ID: ae334d68-59d9-542e-af74-176b152bfea5

STIX ID: report--ae334d68-59d9-542e-af74-176b152bfea5

Feed Name: The Cyber Express

Threat Score
80/100

Date Published: 2026-03-02

Date Updated: 2026-04-23

Author: Samiksha Jain

...
...

CISA's updated analysis of RESURGE malware reports that attackers exploit Ivanti Connect Secure (CVE-2025-0282) to install highly stealthy, dormant implants that use advanced encryption (ECC), forged TLS certificates, SSH tunnels, TLS fingerprinting, CRC32 hashing, file manipulation and web shells to maintain covert command-and-control; the update emphasizes the difficulty of detection and removal and urges organizations to apply patches, perform threat hunting, and deploy updated IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.