logo

Chinese Hackers Exploiting VPN Flaws to Deploy KrustyLoader Malware

ID: 9ee46dc4-0d60-5595-93c2-f0473d97e30b

STIX ID: report--9ee46dc4-0d60-5595-93c2-f0473d97e30b

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-01-31

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A pair of zero-day vulnerabilities in Ivanti Connect Secure VPN appliances (CVE-2023-46805 and CVE-2024-21887) are being actively exploited to achieve unauthenticated remote code execution. Threat actors — including a Chinese nation-state group tracked as UTA0178/UNC5221 — have used the flaws to deploy a Rust loader called KrustyLoader that fetches the Sliver post-exploitation framework; other adversaries have dropped cryptomining and Rust-based malware. Patches were delayed and only temporary mitigations were offered at the time of reporting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.