Threat Advisory

China linked clusters Exploit Ivanti VPN Vulnerabilities

Threat: Vulnerability/Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Researchers has identified two prominent clusters UNC5325 and UNC3886 from China have surged recently with exploiting vulnerabilities in Ivanti Connect Secure VPN appliances. UNC5325 is utilizing CVE-2024-21893 has deployed a series of new malware strains like LITTLELAMB.WOOLTEA and PITSTOP, enabling persistent access to compromised systems. There is moderate confidence that UNC5325 is associated with UNC3886 due to overlaps in the source code of LITTLELAMB.WOOLTEA and PITHOOK malware used by both groups. UNC3886 is known for exploiting zero-day vulnerabilities in Fortinet and VMware solutions and deploys implants like VIRTUALPITA and THINCRUST and this group primarily targeting defense, technology, and telecommunications sectors in the U.S. and Asia-Pacific. Additionally, UNC5325 demonstrated a sophisticated understanding of Ivanti appliances, misusing legitimate components like SparkGateway plugins to drop payloads. Cyber experts warn of ongoing threats from China-based actors, expecting continued exploitation of zero-day vulnerabilities and appliance-specific malware to infiltrate and persist within target environments.[/subscribe_to_unlock_form]

Summary:

Researchers has identified two prominent clusters UNC5325 and UNC3886 from China have surged recently with exploiting vulnerabilities in Ivanti Connect Secure VPN appliances. UNC5325 is utilizing CVE-2024-21893 has deployed a series of new malware strains like LITTLELAMB.WOOLTEA and PITSTOP, enabling persistent access to compromised systems. There is moderate confidence that UNC5325 is associated with UNC3886 due to overlaps in the source code of LITTLELAMB.WOOLTEA and PITHOOK malware used by both groups. UNC3886 is known for exploiting zero-day vulnerabilities in Fortinet and VMware solutions and deploys implants like VIRTUALPITA and THINCRUST and this group primarily targeting defense, technology, and telecommunications sectors in the U.S. and Asia-Pacific. Additionally, UNC5325 demonstrated a sophisticated understanding of Ivanti appliances, misusing legitimate components like SparkGateway plugins to drop payloads. Cyber experts warn of ongoing threats from China-based actors, expecting continued exploitation of zero-day vulnerabilities and appliance-specific malware to infiltrate and persist within target environments.[emaillocker id="1283"]

The malware, identified as libchilkat.so (LITTLELAMB.WOOLTEA), exhibits robust persistence mechanisms, ensuring its survival across system upgrades and resets. Through careful manipulation of system processes and filesystems, the malware maintains its presence even after factory resets, although with dependencies on encryption keys. During system upgrades, the malware intercepts and modifies the upgrade process, embedding itself within the new system's installation files. It hijacks critical system binaries such as tar, ensuring the inclusion of its malicious components in subsequent installations. Furthermore, the malware hooks into the web server process using libaprhelper.so (PITSOCK), enabling covert communication channels for command-and-control operations. The injection of backdoor functionality extends to SparkGateway plugins, exemplified by security.jar (PITDOG), which employs Kubo Injector for memory manipulation and persistence. This plugin establishes a watchdog mechanism, ensuring continuous execution of malicious code within the web process, thereby enabling persistent remote access and control.

The Vulnerabilities in Ivanti VPN infrastructure pose a significant threat to organisation. Addressing these flaws is crucial to prevent unauthorized access and malware deployment, safeguarding sensitive data and assets. Their exploitation of Ivanti vulnerabilities underscores the need for robust cybersecurity measures, including timely patching, continuous monitoring, and threat intelligence sharing.

Threat Profile:

 

References:

The following reports contain further technical details:

https://thehackernews.com/2024/02/chinese-hackers-exploiting-ivanti-vpn.html

[/emaillocker]
crossmenu