LITTLELAMB.WOOLTEA is a stealthy backdoor used to maintain access to compromised enterprise network appliances, particularly Ivanti Connect Secure VPN devices. It has been deployed by UNC5325, a suspected China-nexus cyberespionage actor, during exploitation of Ivanti vulnerabilities, including CVE-2024-21893 chained with CVE-2024-21887. The backdoor supports SSL-encrypted communications using the compromised appliance’s web-server private key, SOCKS proxying, and standalone operation through a Unix-domain socket.
Its persistence mechanisms include appending malicious components to an archive in the appliance’s factory-reset partition. These modifications are intended to preserve access across upgrades, patches, and factory resets; observed Ivanti persistence attempts failed because the malware did not account for an encryption-key mismatch.
A backdoor discovered on a Palo Alto Networks firewall following exploitation of CVE-2024-9474 was assessed as associated with LITTLELAMB.WOOLTEA. That implementation masquerades as a legitimate logging service, modifies startup and upgrade handling, and injects a library into nginx to intercept incoming connections. It recognizes operator traffic through a distinctive handshake, reuses an existing listening port, and encrypts communications using the appliance’s management-interface certificate. Its command set provides interactive shell access, file reading and writing, host-information retrieval, multi-node routing, network tunneling, and SOCKS5-style proxying over the backdoor network. Some tunneling functions were incomplete or nonfunctional in the analyzed implementation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A suspected nation state threat actor gained entry to a Palo Alto network device through CVE-2024-9474, shortly after details of the vulnerability were made public.
Mandiant observed ... development of a mitigation bypass exploit targeting CVE-2024-21893 ... The mitigation bypass is now tracked as CVE-2024-21893. It is a server-side request forgery (SSRF) vulnerability in the SAML component of Ivanti Connect Secure (CS), Policy Secure (PS), and Neurons for Zero Trust Access (NZTA) appliances... Mandiant identified active exploitation of CVE-2024-21893 by UNC5325 as early as Jan. 19, 2024... threat actors chaining the SSRF vulnerability with ... CVE-2024-21887...
Mandiant has identified UNC5325 using a combination of living-off-the-land (LotL) techniques to better evade detection, while deploying novel malware such as LITTLELAMB.WOOLTEA in an attempt to persist across system upgrades, patches, and factory resets.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Mandiant has identified UNC5325 using a combination of living-off-the-land (LotL) techniques to better evade detection, while deploying novel malware such as LITTLELAMB.WOOLTEA in an attempt to persist across system upgrades, patches, and factory resets.
Mandiant has identified UNC5325 using a combination of living-off-the-land (LotL) techniques to better evade detection, while deploying novel malware such as LITTLELAMB.WOOLTEA in an attempt to persist across system upgrades, patches, and factory resets.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
"Aria-body has the ability to use a reverse SOCKS proxy module." / "BADHATCH can use SOCKS4 and SOCKS5 proxies..." / "Neo-reGeorg... establish a SOCKS5 proxy" / "Remcos uses the infected hosts as SOCKS5 proxies"
Aria-body has the ability to use a reverse SOCKS proxy module... BADHATCH can use SOCKS4 and SOCKS5 proxies... GoBear implements SOCKS5 proxy functionality... Neo-reGeorg has the ability to establish a SOCKS5 proxy... Remcos uses the infected hosts as SOCKS5 proxies...
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2").
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that communicates over SSL using a private key taken from an Ivanti Connect Secure web server.
Malware that appends malicious components to a factory reset partition archive to survive device reset.
Communicates over SSL using the private key from an Ivanti Connect Secure web server.
Backdoor that can communicate over SSL using a private key taken from an Ivanti Connect Secure web server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.