logo

Nation-State Actors Weaponize Ivanti VPN Zero-Days, Deploying 5 Malware Families

ID: db52fa39-7b29-56c9-826d-77da6bd7a67b

STIX ID: report--db52fa39-7b29-56c9-826d-77da6bd7a67b

Feed Name: The Hacker News

Threat Score
92/100

Date Published: 2024-01-12

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Mandiant and Volexity report that suspected nation-state actors (tracked as UNC5221 / UTA0178) exploited two Ivanti Connect Secure zero-days (CVE-2023-46805 and CVE-2024-21887) starting in December 2023 to bypass authentication, inject code, and deploy multiple custom malware families and web shells (including LIGHTWIRE, WIREFIRE/GIFTEDVISITOR, WARPWIRE, ZIPLINE), enabling persistent remote access, credential theft, and tunneling; exploitation scaled in January 2024 with Volexity reporting over 1,700 devices compromised across government, telecom, defense, financial, and other sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.