CISA reveals new malware variant used on compromised Ivanti Connect Secure devices
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-0282 | Unauthenticated RCE in Ivanti Connect Secure, Policy Secure, and ZTA Gateways CVE-2025-0282 is a stack-based buffer overflow (CWE-121) in Ivanti Connect Secure, Policy Secure, and ZTA Gateways, reachable by unauthenticated network input. An attacker can trigger it remotely by sending crafted, unauthenticated traffic to a vulnerable gateway, overwriting stack memory and gaining code execution under the appliance's context. Successful exploitation yields unauthenticated remote code execution on the device, giving the attacker control of the VPN/secure-access gateway and a foothold into the protected network. Organizations running any of the affected Ivanti secure-access products are exposed; the source data specifies no version ranges, so defenders should consult Ivanti's advisory for exact affected and fixed releases. The flaw is being actively exploited: it was added to CISA KEV on 2025-01-08 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile), despite no public PoC being known. Do: Apply the patched releases identified in Ivanti's advisory and follow CISA's required action: hunt for signs of compromise, remediate if indicators are found, and apply updates before returning any device to service. Because exploitation is active and ransomware use is known, treat any appliance that was internet-reachable before patching as potentially compromised (check integrity, rotate credentials). Exact fixed versions were not included in the source data, so verify the correct update path for your branch (including older Connect Secure/Policy Secure releases) against Ivanti's bulletin. | 9.0 | 100% | KEV ransomware PoC ×3 |
| largetens of thousands of internet-exposed appliances (likely 100,000+ total deployments including internal-only gateways) |
Full article395 words · extracted from helpnetsecurity.com · click to collapse
CISA has released indicators of compromise, detection signatures, and updated mitigation advice for rooting out a newly identified malware variant used by the attackers who breached Ivanti Connect Secure VPN appliances in December 2024 by exploiting the CVE-2025-0282 zero-day.
The updated mitigation instructions stress the importance of conducting a factory reset of all devices – even those where threat hunting did not reveal evidence of compromise – as well as a factory reset of cloud and virtual systems using an external known clean image of the device.
“CISA updated these mitigations based on identification of a new malware variant called RESURGE that could undermine the effectiveness of the mitigations previously provided,” the US Cybersecurity and Infrastructure Security Agency noted.
Attackers leveraging CVE-2025-0282 as a zero-day
News that attackers have leveraged a zero-day vulnerability (CVE-2025-0282) to breach Ivanti Connect Secure devices broke in early January 2025, when the company patched that and another (not actively exploited) vulnerability and confirmed that a limited number of customers were affected.
Mandiant researchers followed up with more details: the attacks had been undertaken by suspected China-nexus espionage actor(s), which used known and previously unobserved malware to infect and compromise the targeted devices, as well as to assure its persistence on them by modifying components, blocking legitimate system upgrades and symulating fake ones, rewriting executables, circumventing the appliance’s internal Integrity Checker Tool (ICT), etc.
Microsoft’s threat analysts subsequently also tied some of the attacks to the Chinese espionage group Silk Typhoon.
New malware variant tailored for Ivanti Connect Secure devices
“RESURGE contains capabilities of the [previously analyzed] SPAWNCHIMERA malware variant, including surviving reboots; however, RESURGE contains distinctive commands that alter its behavior,” CISA revealed on Friday.
“These commands create a web shell, manipulate integrity checks, and modify files; enable the use of web shells for credential harvesting, account creation, password resets, and escalating permissions, and copy the web shell to the Ivanti running boot disk and manipulate the running coreboot image.”
The RESURGE samples also included a new variant of SPAWNSLOTH (a log tampering utility) and a custom embedded binary containing an open-source shell script and some BusyBox applets.
“The open-source shell script allows for ability to extract an uncompressed kernel image (vmlinux) from a compromised kernel image. BusyBox enables threat actors to perform various functions such as download and execute payloads on compromised devices,” the agency explained.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/03/31/cisa-reveals-new-malware-variant-used-on-compromised-ivanti-connect-secure-devices/