China-Linked Hackers Used ROOTROT Webshell in MITRE Network Intrusion
ID: 62e39628-83b8-58c8-9f3c-cd30e4cfe633
STIX ID: report--62e39628-83b8-58c8-9f3c-cd30e4cfe633
Feed Name: The Hacker News
Threat Score
MITRE disclosed that an adversary linked to UNC5221 exploited two Ivanti Connect Secure zero-days beginning December 31, 2023 to compromise its NERVE research environment, implanted multiple web shells and a Golang backdoor (ROOTROT, BRICKSTORM, BEEFLUSH, WIREFIRE), established persistence on VMware/ESXi hosts, harvested credentials, and attempted lateral movement and data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
