Mirai Botnet Exploits Ivanti Connect Secure Flaws for Malicious Payload Delivery
ID: 01288672-5b80-5bc0-96ed-ec716fc04965
STIX ID: report--01288672-5b80-5bc0-96ed-ec716fc04965
Feed Name: The Hacker News
Juniper Threat Labs observed active exploitation of two Ivanti Connect Secure flaws (CVE-2023-46805 authentication bypass and CVE-2024-21887 command injection) chained to execute arbitrary commands that download and run a shell script, which in turn retrieves the Mirai botnet binary from an actor-controlled IP (192.3.152.183). The report notes the specific API endpoints abused (including /api/v1/license/key-status/ and /api/v1/totp/user-backup-code/) and describes the payload behavior (wiping files, downloading a script, setting execution permissions, and executing it). Separately, SonicWall reported a fake explorer.exe that installs a cryptocurrency miner by dropping files into /Windows/Fonts and using a batch script to start mining.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
