GIFTEDVISITOR, also known as WIREFIRE, is a Python web shell deployed on compromised Ivanti Connect Secure VPN appliances. It modifies a legitimate Python component of the appliance’s web application to provide persistent, HTTP-accessible command execution and file-transfer functionality. It supports uploading and downloading files, executing arbitrary commands, and returning Base64-encoded process output. Variants use AES encryption, with a variant observed during widespread exploitation using victim-specific keys derived from truncated UUID strings.
GIFTEDVISITOR was deployed following exploitation of CVE-2023-46805, an authentication-bypass vulnerability, chained with CVE-2024-21887, a command-injection vulnerability. It has been used in intrusions associated with UTA0178 and UNC5221, including the compromise of MITRE’s NERVE research environment. By January 16, 2024, more than 2,100 Ivanti Connect Secure appliances worldwide had been identified as infected. Affected organizations ranged from small businesses to Fortune 500 companies across government, military, telecommunications, defense, technology, finance, aerospace, and other sectors. The web shell provides continued access to compromised appliances for post-exploitation operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The paired CVE-2023-46805 and CVE-2024-21887 test sends {"type": ";id;"} to a maintenance endpoint. A second request to /api/v1/cav/client/visits contains GIFTEDVISITOR and attempts to trigger a webshell.
The author observed scans attempting to exploit CVE-2023-46805 and CVE-2024-21887, including a traversal-based request to a maintenance endpoint and a request attempting to trigger the GIFTEDVISITOR webshell.
Threat actors are exploiting previously identified vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure gateways, including CVE-2023-46805 (CVSS 8.2), CVE-2024-21887 (CVSS 9.1) and CVE-2024-21893 (CVSS 8.1).
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group has been observed using other distinct malware including CHAINLINE backdoor, FRAMESTING webshell, WIREFIRE webshell.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
They function as dormant backdoors, activated only when attackers submit specific HTTP requests containing commands or credentials.
the adversary executed suspicious Python scripts and /bin/sh commands from the /tmp directory
BEEFLUSH ... communicated with several internal IP addresses making POST requests.
The content repeatedly describes threat actors, malware, and campaigns using HTTP and/or HTTPS for command and control, including examples such as BlackEnergy communicating with C2 over HTTP POST requests and many other families using HTTP/S for C2.
The adversary uploaded a Python script, visits.py, that contained the WIREFIRE (aka GIFTEDVISITOR) web shell
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Webshell mentioned as part of UNC5221's broader malware arsenal; no operational details are provided.
A webshell identified on more than 2,100 compromised Ivanti devices. It is mentioned as context for exploitation affecting Ivanti appliances; the excerpt does not detail its capabilities.
A webshell used to maintain access on compromised Ivanti Connect Secure VPN devices.
A webshell associated with exploitation of Ivanti vulnerabilities CVE-2023-46805 and CVE-2024-21887. The observed honeypot request attempts to trigger it by posting the string GIFTEDVISITOR to /api/v1/cav/client/visits. The content documents an attempted trigger, not a confirmed infection or successful execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.