Warning: New Malware Emerges in Attacks Exploiting Ivanti VPN Vulnerabilities
ID: 828ad7ac-3008-529d-949c-2e9d4dea9e92
STIX ID: report--828ad7ac-3008-529d-949c-2e9d4dea9e92
Feed Name: The Hacker News
Mandiant observed China-nexus actor UNC5221 and other groups exploiting Ivanti Connect Secure and Policy Secure zero-day vulnerabilities (including CVE-2023-46805 and CVE-2024-21887) to deploy multiple web shells and backdoors (CHAINLINE, BUSHWALK, FRAMESTING, LIGHTWIRE variant, WARPWIRE, ZIPLINE) for arbitrary command execution, credential theft, and data exfiltration; vendors and national agencies (Ivanti, BSI, CISA) have issued advisories and mitigations, with CISA ordering urgent disconnects and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
