ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino

New Malware Variant RESURGE Exploits Ivanti Vulnerability

criticalVulnerability exploited in the wildimportance 60CVE-2025-0282

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-0282
Unauthenticated RCE in Ivanti Connect Secure, Policy Secure, and ZTA Gateways

CVE-2025-0282 is a stack-based buffer overflow (CWE-121) in Ivanti Connect Secure, Policy Secure, and ZTA Gateways, reachable by unauthenticated network input. An attacker can trigger it remotely by sending crafted, unauthenticated traffic to a vulnerable gateway, overwriting stack memory and gaining code execution under the appliance's context. Successful exploitation yields unauthenticated remote code execution on the device, giving the attacker control of the VPN/secure-access gateway and a foothold into the protected network. Organizations running any of the affected Ivanti secure-access products are exposed; the source data specifies no version ranges, so defenders should consult Ivanti's advisory for exact affected and fixed releases. The flaw is being actively exploited: it was added to CISA KEV on 2025-01-08 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile), despite no public PoC being known.

Do: Apply the patched releases identified in Ivanti's advisory and follow CISA's required action: hunt for signs of compromise, remediate if indicators are found, and apply updates before returning any device to service. Because exploitation is active and ransomware use is known, treat any appliance that was internet-reachable before patching as potentially compromised (check integrity, rotate credentials). Exact fixed versions were not included in the source data, so verify the correct update path for your branch (including older Connect Secure/Policy Secure releases) against Ivanti's bulletin.

9.0100% KEV ransomware PoC ×3
  • Ivanti Connect Secure
  • Ivanti Policy Secure
  • Ivanti ZTA Gateways
largetens of thousands of internet-exposed appliances (likely 100,000+ total deployments including internal-only gateways)
Full article357 words · extracted from infosecurity-magazine.com · click to collapse

A new malware variant dubbed RESURGE has been uncovered by the US Cybersecurity and Infrastructure Security Agency (CISA) and is targeting Ivanti Connect Secure appliances through a critical vulnerability.

The malware leverages a stack-based buffer overflow flaw,  CVE-2025-0282, to create web shells, manipulate system files and survive system reboots.

CISA’s analysis, revealed that RESURGE shares functionality with the prior SPAWNCHIMERA malware but introduces unique commands to enhance its stealth and persistence.

RESURGE’s capabilities include embedding web shells for credential harvesting, modifying coreboot images to maintain access and evading integrity checks.

The malware injects itself into legitimate processes, creating SSH tunnels for command-and-control (C2) communication. It also copies malicious components to the Ivanti boot disk, ensuring persistence even after restarts.

CISA noted RESURGE’s ability to execute arbitrary commands, including password resets and privilege escalation.

The malware was found alongside a variant of the SPAWNSLOTH log-tampering tool and a custom binary “dsmain,” which incorporates BusyBox utilities. dsmain enables attackers to decrypt and repackage coreboot images, embedding malicious payloads. The analysis also identified RESURGE’s use of open-source tools like extract_vmlinux.sh to modify kernel images, further complicating detection.

CVE-2025-0282 was added to CISA’s Known Exploited Vulnerabilities Catalog on January 8 2025 and affects Ivanti Connect Secure, Policy Secure and ZTA Gateways. Attackers exploit this flaw to gain initial access, after which RESURGE deploys its full toolkit.

CISA urges immediate action, recommending:

  • Factory resets for compromised devices, using clean images for cloud systems
  • Resetting credentials for all accounts, including the krbtgt account (responsible for handling Kerberos ticket requests and encrypting and signing them) twice, with replication delays
  • Temporarily revoking or reducing privileges for affected devices to contain breaches
  • Monitoring administrative accounts for unauthorized activity

The agency also provided YARA and SIGMA detection rules, along with a detailed Malware Analysis Report (MAR-25993211.R1.V1.CLEAR).

Read more on Ivanti’s CVE-2025-0282 vulnerability: Critical Ivanti Zero-Day Exploited in the Wild

Additional guidance includes disabling unnecessary services, enforcing strong passwords and scanning removable media.

CISA emphasized situational awareness of evolving threats, referencing NIST’s malware incident handling standards for broader organizational preparedness.

Users are directed to report incidents via CISA’s Operations Center or submit malware samples to Malware Nextgen.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/malware-resurge-exploits-ivanti/