logo

Mirai Botnet Exploits Ivanti Connect Secure Flaws for Malicious Payload Delivery

ID: 01288672-5b80-5bc0-96ed-ec716fc04965

STIX ID: report--01288672-5b80-5bc0-96ed-ec716fc04965

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-05-09

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Juniper Threat Labs observed active exploitation of two Ivanti Connect Secure flaws (CVE-2023-46805 authentication bypass and CVE-2024-21887 command injection) chained to execute arbitrary commands that download and run a shell script, which in turn retrieves the Mirai botnet binary from an actor-controlled IP (192.3.152.183). The report notes the specific API endpoints abused (including /api/v1/license/key-status/ and /api/v1/totp/user-backup-code/) and describes the payload behavior (wiping files, downloading a script, setting execution permissions, and executing it). Separately, SonicWall reported a fake explorer.exe that installs a cryptocurrency miner by dropping files into /Windows/Fonts and using a batch script to start mining.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.