logo

Chinese Hackers Exploiting Ivanti VPN Flaws to Deploy New Malware

ID: c0794eff-eee4-52d0-88a3-8d5c02bbfe26

STIX ID: report--c0794eff-eee4-52d0-88a3-8d5c02bbfe26

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2024-02-29

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Mandiant and other vendors report that China-linked clusters (UNC5325 and UNC3886) have actively exploited zero-day flaws in Ivanti Connect Secure appliances—notably CVE-2024-21893 (SSRF) combined with CVE-2024-21887—to deploy multiple appliance-specific implants (LITTLELAMB.WOOLTEA, PITHOOK, PITSTOP, BUSHWALK, etc.), attempt persistence via malicious SparkGateway plugins, and target high-value sectors (defense, telecommunications, critical infrastructure); the report also notes links between this activity and other China-associated operations such as Volt Typhoon and UTA0178.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.