Chinese Hackers Exploiting Ivanti VPN Flaws to Deploy New Malware
ID: c0794eff-eee4-52d0-88a3-8d5c02bbfe26
STIX ID: report--c0794eff-eee4-52d0-88a3-8d5c02bbfe26
Feed Name: The Hacker News
Mandiant and other vendors report that China-linked clusters (UNC5325 and UNC3886) have actively exploited zero-day flaws in Ivanti Connect Secure appliances—notably CVE-2024-21893 (SSRF) combined with CVE-2024-21887—to deploy multiple appliance-specific implants (LITTLELAMB.WOOLTEA, PITHOOK, PITSTOP, BUSHWALK, etc.), attempt persistence via malicious SparkGateway plugins, and target high-value sectors (defense, telecommunications, critical infrastructure); the report also notes links between this activity and other China-associated operations such as Volt Typhoon and UTA0178.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
