216.73.216.6

Malware Identified in Attacks Exploiting Ivanti Connect Secure Vulnerabilities

· Published 18/07/2025 07:33 · Modified 18/07/2025 09:21

Export JSON

Essential information

Published
18/07/2025 07:33
Modified
18/07/2025 09:21
Tags
2025-07-18 cobalt strike cobalt strike beacon fscan ivanti connect secure mdifyloader vshell
Related entities
3 techniques (mitre), 4 malware

Description

The article details malware and tactics used in attacks targeting vulnerabilities from December 2024 to July 2025. It describes , a loader based on libPeConv, which deploys through DLL side-loading. The attackers also utilized , a multi-platform RAT, and , a network scanning tool. After gaining initial access, the threat actors performed lateral movement using brute-force attacks, exploited vulnerabilities, and used stolen credentials. They established persistence by creating domain accounts and registering malware as services or scheduled tasks. The attackers employed various evasion techniques, including the use of legitimate files and ETW bypasses.

External references