Threat Advisory

Ivanti’s Connect Secure And Policy Secure Zero-days Exploited in Attacks

Threat: Vulnerability/Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Ivanti has disclosed two zero-day vulnerabilities affecting Connect Secure (ICS) and Policy Secure (IPS), exploited by suspected Chinese hackers, enabling remote execution of arbitrary commands on targeted gateways. The first flaw CVE-2023-46805 is an authentication bypass in the web component, allowing unauthorized access to resources. The second CVE-2024-21887 is a command injection vulnerability, enabling authenticated admins to execute arbitrary commands. When combined, threat actors can run arbitrary commands on all supported versions of ICS VPN and IPS NAC appliances.[/subscribe_to_unlock_form]

Summary:

Ivanti has disclosed two zero-day vulnerabilities affecting Connect Secure (ICS) and Policy Secure (IPS), exploited by suspected Chinese hackers, enabling remote execution of arbitrary commands on targeted gateways. The first flaw CVE-2023-46805 is an authentication bypass in the web component, allowing unauthorized access to resources. The second CVE-2024-21887 is a command injection vulnerability, enabling authenticated admins to execute arbitrary commands. When combined, threat actors can run arbitrary commands on all supported versions of ICS VPN and IPS NAC appliances.[emaillocker id="1283"]

The attackers strategically modified legitimate components, such as compcheckresult.cgi and lastauthserverused.js, for malicious purposes. Compcheckresult.cgi was backdoored to permit remote code execution over the Internet, while lastauthserverused.js was altered to capture and exfiltrate user credentials. The deployment of webshells, specifically GLASSTOKEN versions 1 and 2, served as the primary method for persistent access. These webshells allowed the threat actor to execute arbitrary PowerShell commands and manipulate system components. The attackers engaged in extensive lateral movement, employing compromised credentials for RDP, SMB, and SSH connections to internal systems. Notably, they conducted reconnaissance through proxied connections, downloaded tools from compromised appliances, and used reverse SOCKS proxy and SSH tunnel connections.

The timeline of events reveals a rapid progression from the earliest observed exploitation to the recent discovery of mass exploitation by UTA0178. Despite initial assessments suggesting limited exploitation, subsequent findings indicate a surge in scanning activities by threat actors, leading to the identification of compromised ICS VPN appliances. Researchers’ methodology, including scans and the development of a new detection method, uncovered evidence of compromise on over 1,700 devices worldwide. The attackers, suspected to be UTA0178, demonstrated a high level of sophistication by employing a slightly modified variant of the GIFTEDVISITOR webshell, replacing the AES key with a truncated UUID string. Additionally, concerning revelations indicate that multiple threat actors, beyond UTA0178, now possess access to the exploit and are actively attempting to compromise devices. Logs analysis points to nearly two dozen IP addresses with attempted exploitation, suggesting the proliferation of the exploit beyond the initial threat actor.

UNC5221 leveraged the vulnerabilities to deploy custom malware, including ZIPLINE, a passive backdoor with various functionalities such as file upload/download, reverse shell creation, and proxy server establishment. Another tool, THINSPOOL, acted as a dropper for the LIGHTWIRE web shell, facilitating arbitrary command execution. LIGHTWIRE, written in Perl CGI, intercepted specific requests, and executed commands. WIREFIRE, a Python-based web shell, supported file downloads and command execution, utilizing unique evasion techniques. Additionally, the WARPWIRE JavaScript credential harvester targeted plaintext passwords and usernames for exfiltration. The attacker demonstrated a sophisticated approach to maintain persistence, evasion, and continued access.

 

The recent attacks orchestrated by UTA0178 and UNC5221 highlight the evolving sophistication of nation-state-level threat actors. The widespread exploitation of ICS VPN and Ivanti vulnerabilities underscores the urgency for organizations to promptly address vulnerabilities, apply mitigations, and adopt a holistic cybersecurity approach. Proactive defense strategies, continuous vigilance, and collaboration within the security community are essential to counter these advanced threats. The threat advisory emphasizes the need for immediate action, including patching, post-incident analysis, and adherence to recommended mitigation measures, reflecting the dynamic and persistent nature of contemporary cybersecurity challenges.

Recommendations:

  • Until patches are available, the zero-days can be mitigated by importing migitigation.release.20240107.1.xml file available to customers via Ivanti's download portal.

Threat Profile:

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/ivanti-warns-of-connect-secure-zero-days-exploited-in-attacks/

https://www.volexity.com/blog/2024/01/15/ivanti-connect-secure-vpn-exploitation-goes-global/

https://www.bleepingcomputer.com/news/security/ivanti-connect-secure-zero-days-now-under-mass-exploitation/

https://www.bleepingcomputer.com/news/security/ivanti-connect-secure-zero-days-exploited-to-deploy-custom-malware/

https://thehackernews.com/2024/01/nation-state-actors-weaponize-ivanti.html

[/emaillocker]
crossmenu