Attackers exploited Ivanti Connect Secure zero-days CVE-2023-46805 and CVE-2024-21887 to gain initial access and launch extensive follow-on activity, including in MITRE's NERVE research network. MITRE said the intrusion overlapped with Mandiant reporting on the China-nexus espionage actor UNC5221 and began with exploitation of the Ivanti appliance, deployment of the ROOTROT web shell, MFA bypass, and use of HTML5-based RDP access. The attackers then profiled VMware infrastructure, used compromised administrative credentials, manipulated virtual machines, and staged data for exfiltration through the Ivanti help site before moving data out through command-and-control infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
22 events from the most recent confirmed update back to the earliest known activity.
MITRE published a technical analysis of the intrusion into its NERVE research network, linking observed activity to overlaps with Mandiant's reporting on UNC5221 and disclosing novel findings on malware including BEEFLUSH and a BUSHWALK variant.
On April 4, 2024, Mandiant reported UNC5266 as a cluster involved in post-disclosure exploitation of Ivanti Connect Secure vulnerabilities, linked to deployment of Bishop Fox's SLIVER, a WARPWIRE variant, and the new TERRIBLETEA malware family. Mandiant said it suspected with moderate confidence that UNC5266 partially overlaps with China-nexus espionage actor UNC3569.
Mandiant said that since the January 10, 2024 disclosure it had tracked eight distinct clusters exploiting one or more Ivanti vulnerabilities, including multiple suspected China-nexus and financially motivated actors.
By April 3, 2024, Ivanti had released an enhanced external Integrity Checker Tool to help detect malware persistence attempts across factory resets and upgrades, and Mandiant recommended running it alongside the internal ICT.
As of April 3, 2024, patches were available for every supported Ivanti Connect Secure version affected by the referenced vulnerabilities.
In April 2024, MITRE publicly confirmed that one of its research and prototyping networks had been compromised via Ivanti Connect Secure zero-days and said it had isolated affected systems, engaged third-party DFIR support, and begun broader containment and forensic work. MITRE said the investigation was ongoing and that prior hardening of the Ivanti system had not prevented the attacker's lateral movement into VMware infrastructure.
On February 3, 2024, UNC5330 attempted to download Fast Reverse Proxy (FRP) from an actor-controlled server using a compromised Ivanti Connect Secure device.
MBSD-SOC reported that exploitation attempts against Ivanti Connect Secure and Ivanti Policy Secure increased again in February 2024 after declining in late January. The firm linked the resurgence to disclosure of additional vulnerabilities including CVE-2024-21888, CVE-2024-21893, and CVE-2024-22024, and observed command injection and SSRF-style exploit traffic.
Mandiant observed suspected China-nexus actor UNC5330 compromising Ivanti Connect Secure appliances as early as February 2024 by chaining CVE-2024-21893 and CVE-2024-21887.
In February 2024, Mandiant created the UNC5291 cluster and assessed with medium confidence that it is Volt Typhoon, noting targeting of U.S. energy and defense sectors.
On 2024-01-29, Synacktiv published reverse-engineering details on a Rust-based downloader it named KrustyLoader, found on Ivanti Connect Secure appliances compromised via CVE-2023-46805 and CVE-2024-21887. The analysis said the malware self-deletes, performs execution checks, decrypts a hardcoded URL, downloads and decrypts a second stage that is typically a Sliver backdoor, and released a static extractor script and YARA rule.
On January 19, 2024, CISA issued Emergency Directive 24-01 ordering federal civilian agencies to mitigate Ivanti Connect Secure and Ivanti Policy Secure vulnerabilities. The directive marked a formal U.S. government response to active exploitation of the flaws.
MBSD-SOC reported observing attacks in the wild targeting Ivanti Connect Secure and Ivanti Policy Secure vulnerabilities CVE-2023-46805 and CVE-2024-21887 beginning on January 17, 2024. The firm said attack volume rose sharply on January 19 and 20, and captured payloads attempting authentication bypass and access to system information.
On January 11, 2024, the adversary used the Ivanti appliance's /dana-na/help/ path as a staging area for exfiltration and uploaded a Python script named visits.py containing the WIREFIRE/GIFTEDVISITOR web shell.
On January 10, 2024, Ivanti publicly disclosed the two Ivanti Connect Secure zero-day vulnerabilities CVE-2023-46805 and CVE-2024-21887.
On January 7, 2024, the adversary accessed VMs and deployed the BRICKSTORM backdoor and the BEEFLUSH web shell, while also creating three new VMs aligned with local naming conventions and deleting one the same day.
On January 5, 2024, the attacker used compromised administrative credentials from an internal NERVE IP address, attempted to enable SSH, and tried to destroy one of its own VMs while manipulating VMware infrastructure.
On January 4, 2024, the adversary profiled the NERVE environment from the compromised Ivanti appliance, interacted with vCenter, communicated with ESXi hosts, and used hijacked credentials to access accounts and map the network.
Mandiant said UNC5291, which it assessed with medium confidence as Volt Typhoon, probed Ivanti Connect Secure appliances in mid-January 2024 after previously targeting Citrix NetScaler ADC in December 2023.
Mandiant reported that the suspected China-nexus espionage actor UNC5337 compromised Ivanti Connect Secure VPN appliances as early as January 2024.
On December 31, 2023, the adversary exploited CVE-2023-46805 and CVE-2024-21887, bypassed MFA, and deployed the ROOTROT web shell on an external-facing Ivanti Connect Secure appliance to gain initial access to MITRE's NERVE environment.
Mandiant reported that UNC5221 was the only group it observed exploiting CVE-2023-46805 and CVE-2024-21887 before public disclosure, with activity beginning in early December 2023.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
medium.com
Open sourcemedium.com
Open sourcecloud.google.com
Open sourcecloud.google.com
Open sourcesynacktiv.com
Open sourcecisa.gov
Open sourcecve.mitre.org
Open sourceservices.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.