"Ivanti VPN Vulnerabilities Spark Malware Attacks and Federal Agency Orders"

1 min read
Source: The Hacker News
"Ivanti VPN Vulnerabilities Spark Malware Attacks and Federal Agency Orders"
Photo: The Hacker News
TL;DR Summary

Mandiant has discovered new malware used by UNC5221 and other threat groups to exploit Ivanti Connect Secure VPN and Policy Secure devices, including custom web shells like BUSHWALK, CHAINLINE, and FRAMESTING, as well as a variant of LIGHTWIRE. The malware exploits vulnerabilities allowing arbitrary command execution and JavaScript-based credential stealing. The attacks involve open-source utilities for post-exploitation activities, and Ivanti has disclosed and released fixes for additional security flaws. UNC5221 targets various industries of strategic interest to China, with infrastructure and tooling overlapping with past intrusions linked to China-based espionage actors.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

2 min

vs 3 min read

Condensed

77%

40391 words

Want the full story? Read the original article

Read on The Hacker News