logo

Researchers Identify Multiple China Hacker Groups Exploiting Ivanti Security Flaws

ID: a9bedd35-cb62-53d4-93b1-e393e566acd2

STIX ID: report--a9bedd35-cb62-53d4-93b1-e393e566acd2

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-04-05

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Multiple China-linked espionage and financially motivated clusters have been observed exploiting zero-day vulnerabilities in Ivanti Connect Secure appliances (CVE-2023-46805, CVE-2024-21887, CVE-2024-21893) to gain persistent access; attackers deployed custom backdoors and tooling (PHANTOMNET, TONERJAM, SPAWN suite, BRICKSTORM, TERRIBLETEA), used web shells and WMI/LDAP abuse for lateral movement and persistence, and targeted across academic, energy, defense, and health sectors—demonstrating active, sophisticated exploitation of edge appliances to enable long-term intrusion and evasion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.