216.73.216.6

DslogdRAT Malware Installed in Ivanti Connect Secure

· Published 28/04/2025 16:27 · Modified 28/04/2025 19:20

Export JSON

Essential information

Published
28/04/2025 16:27
Modified
28/04/2025 19:20
Tags
2025-04-28 CVE-2025-0282 CVE-2025-22457 c2 communication dslogdrat ivanti connect secure spawnchimera spawnsnare web shell zero-day
Related entities
1 intrusion sets (apt), 1 techniques (mitre), 1 malware, 1 others

Description

The article discusses a malware called , which was installed on systems by exploiting . The malware communicates with a C2 server during business hours to avoid detection. It uses a for initial access and supports various commands for file operations, shell execution, and proxy functionality. The article details the malware's execution flow, configuration data, and communication method. Additionally, malware was found on the same compromised systems. The attacks are potentially linked to the UNC5221 threat group, and organizations are advised to monitor for ongoing threats targeting vulnerabilities.

External references