Nation-State Actors Weaponize Ivanti VPN Zero-Days, Deploying 5 Malware Families
ID: db52fa39-7b29-56c9-826d-77da6bd7a67b
STIX ID: report--db52fa39-7b29-56c9-826d-77da6bd7a67b
Feed Name: The Hacker News
Mandiant and Volexity report that suspected nation-state actors (tracked as UNC5221 / UTA0178) exploited two Ivanti Connect Secure zero-days (CVE-2023-46805 and CVE-2024-21887) starting in December 2023 to bypass authentication, inject code, and deploy multiple custom malware families and web shells (including LIGHTWIRE, WIREFIRE/GIFTEDVISITOR, WARPWIRE, ZIPLINE), enabling persistent remote access, credential theft, and tunneling; exploitation scaled in January 2024 with Volexity reporting over 1,700 devices compromised across government, telecom, defense, financial, and other sectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
