logo

China-Linked Hackers Used ROOTROT Webshell in MITRE Network Intrusion

ID: 62e39628-83b8-58c8-9f3c-cd30e4cfe633

STIX ID: report--62e39628-83b8-58c8-9f3c-cd30e4cfe633

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-05-07

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

MITRE disclosed that an adversary linked to UNC5221 exploited two Ivanti Connect Secure zero-days beginning December 31, 2023 to compromise its NERVE research environment, implanted multiple web shells and a Golang backdoor (ROOTROT, BRICKSTORM, BEEFLUSH, WIREFIRE), established persistence on VMware/ESXi hosts, harvested credentials, and attempted lateral movement and data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.