LITTLELAMB.WOOLTEA is a backdoor malware observed on compromised Ivanti Connect Secure appliances. It can operate as a stand-alone backdoor communicating over the local Unix socket /tmp/clientsDownload.sock, communicate over SSL using the private key from the Ivanti Connect Secure web server, and function as a SOCKS proxy. For persistence, it can append malicious components to the tmp/tmpmnt/bin/samba_upgrade.tar archive inside the factory reset partition in an attempt to survive upgrades, patches, and factory resets. Mandiant reported UNC5325 deploying LITTLELAMB.WOOLTEA during exploitation of Ivanti zero-day vulnerabilities in early 2024, and assessed UNC5325 as a suspected Chinese cyber espionage operator with moderate-confidence links to UNC3886 based on TTP and malware code overlaps. Mandiant stated observed persistence attempts were not successful due to a malware logic issue involving an encryption key mismatch. A later update cited Northwave reporting a Chinese state-sponsored nexus exploiting CVE-2024-9474 to deploy LITTLELAMB.WOOLTEA to maintain access to enterprise networks in cyberespionage campaigns. High-confidence behaviors directly mentioned include SSL-based C2 using the appliance web server private key, SOCKS proxy capability, stand-alone backdoor functionality via /tmp/clientsDownload.sock, and persistence attempts via modification of samba_upgrade.tar in the factory reset partition.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Mandiant observed ... development of a mitigation bypass exploit targeting CVE-2024-21893 ... The mitigation bypass is now tracked as CVE-2024-21893. It is a server-side request forgery (SSRF) vulnerability in the SAML component of Ivanti Connect Secure (CS), Policy Secure (PS), and Neurons for Zero Trust Access (NZTA) appliances... Mandiant identified active exploitation of CVE-2024-21893 by UNC5325 as early as Jan. 19, 2024... threat actors chaining the SSRF vulnerability with ... CVE-2024-21887...
Mandiant has identified UNC5325 using a combination of living-off-the-land (LotL) techniques to better evade detection, while deploying novel malware such as LITTLELAMB.WOOLTEA in an attempt to persist across system upgrades, patches, and factory resets.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Mandiant has identified UNC5325 using a combination of living-off-the-land (LotL) techniques to better evade detection, while deploying novel malware such as LITTLELAMB.WOOLTEA in an attempt to persist across system upgrades, patches, and factory resets.
Mandiant has identified UNC5325 using a combination of living-off-the-land (LotL) techniques to better evade detection, while deploying novel malware such as LITTLELAMB.WOOLTEA in an attempt to persist across system upgrades, patches, and factory resets.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
"Aria-body has the ability to use a reverse SOCKS proxy module." / "BADHATCH can use SOCKS4 and SOCKS5 proxies..." / "Neo-reGeorg... establish a SOCKS5 proxy" / "Remcos uses the infected hosts as SOCKS5 proxies"
Aria-body has the ability to use a reverse SOCKS proxy module... BADHATCH can use SOCKS4 and SOCKS5 proxies... GoBear implements SOCKS5 proxy functionality... Neo-reGeorg has the ability to establish a SOCKS5 proxy... Remcos uses the infected hosts as SOCKS5 proxies...
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2").
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that communicates over SSL using a private key taken from an Ivanti Connect Secure web server.
Malware that appends malicious components to a factory reset partition archive to survive device reset.
Communicates over SSL using the private key from an Ivanti Connect Secure web server.
Backdoor that can communicate over SSL using a private key taken from an Ivanti Connect Secure web server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.