How a noisy ransomware intrusion exposed a long-term espionage foothold
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-38035 | Authentication Bypass in Ivanti Sentry (MobileIron Sentry) Admin Interface Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass (CWE-863) caused by an insufficiently restrictive Apache HTTPD configuration on the product's administrative interface. An attacker triggers the flaw by sending crafted HTTP requests to the administrative interface, which the permissive web server configuration serves without properly enforcing authentication controls. Successful exploitation grants unauthenticated administrative access to the Sentry management interface, giving attackers a foothold in the MDM infrastructure. Any organization running Ivanti Sentry is affected, with risk highest where the administrative interface is reachable from the internet. Exploitation is confirmed: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-08-22 with known ransomware use, and EPSS currently rates the 30-day exploitation probability at 100% (percentile 100) even though no public PoC is known. Do: Apply the mitigations prescribed in Ivanti's security advisory, including the corrective Apache HTTPD configuration and any patched Sentry release the vendor directs you to, or discontinue use of the product if mitigations are unavailable per the CISA KEV required action. Restrict or remove internet exposure of the Sentry administrative interface and review access logs for unauthenticated requests to the admin interface indicating attempted or successful exploitation. | 9.8 | 100% | KEV ransomware PoC |
| moderateroughly 1,000-10,000 internet-exposed Ivanti Sentry deployments (on the order of a few thousand) | |
| CVE-2024-21887 | Command Injection RCE in Ivanti Connect Secure and Policy Secure Ivanti Connect Secure (formerly Pulse Connect Secure) and Ivanti Policy Secure appliances contain a command injection flaw (CWE-77) in their web components, triggered when an authenticated administrator sends crafted requests to the appliance. The bug can be chained with the separate authentication bypass CVE-2023-46805, allowing an unauthenticated attacker to achieve the same result. Successful exploitation lets an attacker execute arbitrary commands and code on the appliance, providing a foothold into the networks behind the VPN or network access control gateway. Any organization running these appliances, typically enterprises and government agencies often deployed directly on the internet perimeter, is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-10 with known ransomware use and EPSS assigns a 100% probability of exploitation within 30 days, although no public proof-of-concept is available. Do: Apply Ivanti's mitigations or patched builds immediately per vendor instructions, addressing the chained authentication bypass CVE-2023-46805 at the same time, and discontinue or restrict use of any appliance for which mitigations are unavailable, especially if it is internet-facing. Because exploitation with ransomware use is known, assume compromise is possible: review appliance web logs for suspicious requests and run Ivanti's integrity-checking guidance to verify appliance images before and after remediation. Where feasible, restrict direct internet exposure of the appliance web interface and monitor for further vendor advisories. | 9.1 | 100% | KEV ransomware PoC |
| largetens of thousands of appliances (roughly 20,000-30,000 internet-exposed ICS gateways at disclosure; total deployed base likely higher) | |
| CVE-2025-4428 +1 in the same advisory: …4427 | Authenticated Code Injection RCE in Ivanti Endpoint Manager Mobile (EPMM) API CVE-2025-4428 is a code injection flaw (CWE-94) in the API component of Ivanti Endpoint Manager Mobile (EPMM) that lets an authenticated, low-privileged remote attacker execute arbitrary code by sending crafted API requests. Successful exploitation yields code execution on the MDM server itself (CVSS 8.8, High), which typically holds device inventory and administrative control over an organization's enrolled mobile fleet. Any organization running EPMM 12.5.0.0 or earlier is in scope. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-05-19, EPSS puts the 30-day exploitation probability at 86% (100th percentile), and public reporting ties limited attacks to the China-linked actor UNC5221, who reportedly began exploiting it alongside the companion API authentication bypass CVE-2025-4427 shortly after disclosure. CISA has also warned that threat actors exploiting these EPMM flaws deploy two malware strains; ransomware involvement has not been confirmed. Do: Upgrade every EPMM instance running 12.5.0.0 or earlier to the patched release per Ivanti's security advisory, prioritizing internet-facing servers, and note that federal agencies must satisfy the BOD 22-01 required action (patch, apply vendor mitigations, or discontinue use of the product). If patching is delayed, restrict internet exposure of the API and review EPMM logs and the advisory's indicators of compromise, since attackers have chained this flaw with the CVE-2025-4427 authentication bypass and deployed malware. Treat any unpatched, exposed EPMM instance as actively targeted until it is remediated. | 8.8 group max | 86% | KEV |
| largetens of thousands of enterprise deployments (order of 10k-100k EPMM servers; many are internet-exposed) | |
| CVE-2025-53770 | Unauthenticated Deserialization RCE in Microsoft SharePoint Server on-premises CVE-2025-53770 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft SharePoint Server on-premises that allows an unauthorized attacker to execute code over a network. It is triggered when the server deserializes attacker-controlled data, can be chained with CVE-2025-53771, and it bypasses the fixes issued for CVE-2025-49704, meaning the earlier patches are insufficient. Successful exploitation yields remote code execution on the SharePoint server, and ransomware operators are known to be using it. Any organization running SharePoint Server on-premises is affected, particularly internet-facing deployments and end-of-life versions such as SharePoint Server 2013 and earlier that can no longer be patched. The flaw is being actively exploited — it was added to CISA's KEV on 2025-07-20 with known ransomware use — and EPSS assigns it a 100% probability of exploitation within 30 days. Do: Apply Microsoft's updated SharePoint Server security updates that fix CVE-2025-53770 — these include more robust protection than the earlier CVE-2025-49704 updates — and ensure the companion CVE-2025-53771 is also addressed, following CISA and vendor mitigation instructions for supported versions. Disconnect public-facing SharePoint Server 2013 or earlier (EOL/EOS) instances, minimize internet exposure of supported servers, and hunt for signs of compromise given the known ransomware exploitation. | 9.8 | 100% | KEV ransomware PoC ×3 |
| mass≈25,000–100,000 internet-exposed on-premises SharePoint servers (public internet-wide scans); total on-prem installed base plausibly >1M users |
Full article563 words · extracted from helpnetsecurity.com · click to collapse
Getting breached by two separate and likely unconnected cyber attack groups is a nightmare scenario for any organization, but can result in an unexpected silver lining: the noisier intrusion can draw attention to a far stealthier threat that might otherwise linger undetected for months.
A double whammy
In a recently published report, threat researchers at Positive Technologies have detailed the findings of their investigation into two incidents at Russian companies, which they have tied to:
- QuietCrabs, a threat actor believed to be of Asian origin and concentrating on cyber espionage, and
- Thor, a threat group that has been targetting Russian companies with LockBit and Babuk ransomware.
Both groups exploited publicly known vulnerabilities in Microsoft Sharepoint Server (CVE-2025-53770) and Ivanti’s solutions (CVE-2024-21887, CVE-2025-4427, CVE-2025-4428, CVE-2023-38035) to achieve initial access.
QuietCrabs attack flow (Source: Positive Technologies)
QuietCrabs leveraged an ASPX web shell, the KrustyLoader (loader) malware, and the Sliver command & control implant. Thor, on the other hand, uses well-known and widely used tools:
- The ADRecon utility (for Active Directory domain reconnaissance)
- The GodPotato tool (for privilege escalation)
- Secretsdump and Mimikatz (for data extraction)
- Tactical RMM and MeshAgent (for persistence), and
- Rclone (for data exfiltration.)
In this case, though, Thor’s presence was detected early enough to foil the deployment of ransomware.
“QuietCrabs and the presumed Thor group operated in almost the same time period. The gap between their malicious activities was only a few days,” the threat researchers noted (though didn’t mention when the attacks actually happened).
“It is also important that the investigation began at the point where Thor activity was first registered. In other words, QuietCrabs could have remained inside the infrastructure for much longer if not for Thor. According to Mandiant’s investigations, QuietCrabs’ average dwell time in victim infrastructure is 393 days.”
The researchers are almost entirely certain that one of the intrusions was by QuietCrabs, as the KrustyLoader is unique malware that’s associated with that group. “Some vendors describe KrustyLoader exclusively as Linux malware. In our case, however, all incident artifacts were Windows samples,” they shared.
The other, more noisy activity has been attributed to Thor based on indicators of compromise that matched a previous attack report by another Russian cybersecurity company.
Thor attack flow (Source: Positive Technologies)
ToolShell: A magnet for various threat actors
In July 2025, after reports of CVE-2025-53770 (aka ToolShell) having been exploited as a zero-day by Chinese threat actors Linen Typhoon and Violet Typhoon against organizations worldwide, Microsoft confirmed that a financially motivated China-based threat actor (Storm 2603) has also been using the vulnerability to achieve access and deploy Warlock ransomware.
“We cannot confidently state that QuietCrabs is collaborating with Thor. In this case, the overlap is most likely coincidental, as both QuietCrabs and Thor conduct broad scans of organizations for subsequent compromise,” the PT researchers opined.
While they say that QuietCrabs has been targeting organizations in the US, UK, Germany, South Korea, Russia, Taiwan, the Philippines, Iran, the Czech Republic, and a number of other countries, Thor’s victims appear to be mostly Russian orgs.
“We were able to identify around 110 Russian companies as potential victims. The affected organizations varied greatly both in economic sector and in the potential profit they offered the attackers,” they concluded.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/12/02/threat-research-ransomware-espionage-attack/