logo

Ivanti Vulnerability Exploited to Install 'DSLog' Backdoor on 670+ IT Infrastructures

ID: 46de5019-a96d-5e3d-b6dd-b2f98db9189f

STIX ID: report--46de5019-a96d-5e3d-b6dd-b2f98db9189f

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2024-02-13

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**Ivanti SSRF (CVE-2024-21893) exploited to deploy DSLog backdoor:** Threat actors are actively exploiting a recently disclosed SSRF in Ivanti Connect/Policy Secure (CVE-2024-21893) to modify a legitimate Perl logging module (DSLog.pm) and install a persistent backdoor named DSLog that executes decoded commands as root, embeds per-appliance hashes to evade detection, and erases logs to cover tracks; Orange Cyberdefense observed compromises starting Feb 3 and detected hundreds of affected appliances (670 initially, 524 later), and vendors recommend factory resetting appliances before applying patches to remove attacker persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.