Summary:
Ivanti has disclosed two critical vulnerabilities, CVE-2023-46805 and CVE-2024-21887, impacting their Connect Secure VPN and Policy Secure appliances. These vulnerabilities, exploited by threat actor UNC5221 pose severe risks including authentication bypass and command injection, potentially leading to extensive network compromise. Researcher's investigation has uncovered sophisticated post-exploitation activities and custom malware families associated with these vulnerabilities, emphasizing the urgent need for mitigation measures and heightened awareness among affected parties.[/subscribe_to_unlock_form]
Summary:
Ivanti has disclosed two critical vulnerabilities, CVE-2023-46805 and CVE-2024-21887, impacting their Connect Secure VPN and Policy Secure appliances. These vulnerabilities, exploited by threat actor UNC5221 pose severe risks including authentication bypass and command injection, potentially leading to extensive network compromise. Researcher's investigation has uncovered sophisticated post-exploitation activities and custom malware families associated with these vulnerabilities, emphasizing the urgent need for mitigation measures and heightened awareness among affected parties.[emaillocker id="1283"]
UNC5221's exploitation of CVE-2023-46805 and CVE-2024-21887 involves leveraging custom malware families such as ZIPLINE, THINSPOOL, and web shells like LIGHTWIRE and WIREFIRE. These malicious tools enable persistent access and command execution on compromised Ivanti devices. ZIPLINE, for instance, operates as a passive backdoor by hijacking system functions, while THINSPOOL acts as a dropper for the LIGHTWIRE web shell, facilitating ongoing compromise. Furthermore, UNC5221 employs techniques to evade detection, including trojanizing legitimate files and targeting out-of-support VPN appliances for command and control (C2) infrastructure, underscoring the sophistication of this espionage-motivated campaign. These vulnerabilities allow threat actors to execute arbitrary commands on the affected appliances with elevated privileges, paving the way for unauthorized access and potential system compromise. Researcher's investigations have uncovered various post-exploitation activities conducted by threat groups, including the deployment of custom web shells such as BUSHWALK, CHAINLINE, and FRAMESTING. These web shells enable threat actors to execute commands, write files, and maintain persistent access to compromised systems.
Moreover, researchers have observed the usage of open-source tools like IMPACKET, CRACKMAPEXEC, IODINE, and ENUM4LINUX for reconnaissance, lateral movement, and data exfiltration within compromised environments. Additionally, modifications to the Ivanti Connect Secure Python package have been identified to support web shell backdoors, further highlighting the sophistication of the attack tactics employed by threat actors.
The recent exploitation activity, particularly by UNC5221 utilizing zero-day vulnerabilities, emphasizes the urgent need for organizations to swiftly mitigate risks by applying patches from Ivanti and implementing provided mitigations. As demonstrated by the tactics employed, including code injection into legitimate files, organizations must remain vigilant and proactive in their cybersecurity efforts to defend against evolving threats. By prioritizing the deployment of patches, running integrity checks, and resetting passwords, organizations can significantly enhance their security posture and safeguard their network infrastructure from potential attacks. This campaign underscores the ongoing imperative for proactive cybersecurity measures to mitigate risks and protect against sophisticated threats in today's dynamic threat landscape.
Recommendations:
Threat Profile:

References:
The following reports contain further technical details:
https://www.mandiant.com/resources/blog/investigating-ivanti-zero-day-exploitation
https://www.mandiant.com/resources/blog/suspected-apt-targets-ivanti-zero-day
[/emaillocker]