GIFTEDVISITOR, also known as WIREFIRE, is a Python-based web shell used on compromised Ivanti Connect Secure VPN appliances. It has been observed in exploitation chains involving CVE-2023-46805 and CVE-2024-21887, where attackers implanted web shells to maintain access after unauthenticated remote compromise. The malware supports arbitrary command execution and file upload or download operations on the compromised device, and it can Base64-encode process output for command-and-control communications. It has been associated with large-scale intrusions affecting internet-facing Ivanti appliances across a wide range of sectors, from small businesses to Fortune 500 organizations, and reporting has linked related activity to the China-nexus espionage cluster UNC5221. GIFTEDVISITOR has been used as a persistence and post-exploitation mechanism on edge infrastructure, enabling continued operator access and follow-on activity after initial exploitation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-46805 is an authentication bypass vulnerability in the web component of Ivanti Connect Secure (ICS), previously known as Pulse Connect Secure and Ivanti Policy Secure. This vulnerability allows an attacker to bypass control checks and access restricted resources. | Volexity also published a follow-up blog post on January 15 into attacks involving CVE-2024-21887 and CVE-2023-46805. According to Volexity, exploitation of these flaws is now “widespread” globally, which includes the compromise of over 1,700 Ivanti Connect Secure (ICS) appliances, including the use of a variant of the webshell called GIFTEDVISITOR.
CVE-2024-21887 is a command injection vulnerability in the web component of Ivanti ICS and Policy Secure that can be abused to execute arbitrary commands by an authenticated user. | Volexity also published a follow-up blog post on January 15 into attacks involving CVE-2024-21887 and CVE-2023-46805. According to Volexity, exploitation of these flaws is now “widespread” globally, which includes the compromise of over 1,700 Ivanti Connect Secure (ICS) appliances, including the use of a variant of the webshell called GIFTEDVISITOR.
Table 1/3 list a Python package containing WIREFIRE and an HBI entry: "Cav-0.1-py3.6.egg" ... "WIREFIRE web shell".
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
According to Mandiant, UNC5221 has “leveraged multiple custom malware families” which includes LIGHTWIRE, a webshell, THINSPOOL, a webshell dropper, WARPWIRE, a credential harvester, WIREFIRE, another webshell and ZIPLINE, a passive backdoor.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
According to Ivanti and a blog by Volexity, these two vulnerabilities were exploited in the wild in a chained attack for unauthenticated remote code execution (RCE) as early as December 3, 2023. | CVE-2024-21887 is a command injection vulnerability in the web component of Ivanti ICS and Policy Secure that can be abused to execute arbitrary commands by an authenticated user. | CVE-2023-46805 is an authentication bypass vulnerability in the web component of Ivanti Connect Secure (ICS), previously known as Pulse Connect Secure and Ivanti Policy Secure. This vulnerability allows an attacker to bypass control checks and access restricted resources.
They function as dormant backdoors, activated only when attackers submit specific HTTP requests containing commands or credentials.
the adversary executed suspicious Python scripts and /bin/sh commands from the /tmp directory
BEEFLUSH ... communicated with several internal IP addresses making POST requests.
The content repeatedly describes threat actors, malware, and campaigns using HTTP and/or HTTPS for command and control, including examples such as BlackEnergy communicating with C2 over HTTP POST requests and many other families using HTTP/S for C2.
The adversary uploaded a Python script, visits.py, that contained the WIREFIRE (aka GIFTEDVISITOR) web shell
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A webshell used to maintain access on compromised Ivanti Connect Secure VPN devices.
A Python web shell that supports file upload and arbitrary command execution, processing HTTP request bodies for a GIF delimiter and returning output after Base64 encoding, AES encryption, zlib compression, and padding.
A webshell variant used to backdoor compromised Ivanti Connect Secure VPN appliances, enabling persistent unauthorized access.
A variant webshell observed in widespread exploitation of Ivanti Connect Secure appliances.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.