logo

Warning: New Malware Emerges in Attacks Exploiting Ivanti VPN Vulnerabilities

ID: 828ad7ac-3008-529d-949c-2e9d4dea9e92

STIX ID: report--828ad7ac-3008-529d-949c-2e9d4dea9e92

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-02-01

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Mandiant observed China-nexus actor UNC5221 and other groups exploiting Ivanti Connect Secure and Policy Secure zero-day vulnerabilities (including CVE-2023-46805 and CVE-2024-21887) to deploy multiple web shells and backdoors (CHAINLINE, BUSHWALK, FRAMESTING, LIGHTWIRE variant, WARPWIRE, ZIPLINE) for arbitrary command execution, credential theft, and data exfiltration; vendors and national agencies (Ivanti, BSI, CISA) have issued advisories and mitigations, with CISA ordering urgent disconnects and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.