DslogdRAT Malware Installed in Ivanti Connect Secure
Essential information
- Published
- 28/04/2025 16:27
- Modified
- 28/04/2025 19:20
- Tags
- 2025-04-28 CVE-2025-0282 CVE-2025-22457 c2 communication dslogdrat ivanti connect secure spawnchimera spawnsnare web shell zero-day
- Related entities
- 1 intrusion sets (apt), 1 techniques (mitre), 1 malware, 1 others
Description
The article discusses a malware called DslogdRAT, which was installed on Ivanti Connect Secure systems by exploiting CVE-2025-0282. The malware communicates with a C2 server during business hours to avoid detection. It uses a web shell for initial access and supports various commands for file operations, shell execution, and proxy functionality. The article details the malware's execution flow, configuration data, and communication method. Additionally, SPAWNSNARE malware was found on the same compromised systems. The attacks are potentially linked to the UNC5221 threat group, and organizations are advised to monitor for ongoing threats targeting Ivanti Connect Secure vulnerabilities.