NEW: Unlock the Future of Finance with CRYPTO ENDEVR - Explore, Invest, and Prosper in Crypto!
Crypto Endevr
  • Top Stories
    • Latest News
    • Trending
    • Editor’s Picks
  • Media
    • YouTube Videos
      • Interviews
      • Tutorials
      • Market Analysis
    • Podcasts
      • Latest Episodes
      • Featured Podcasts
      • Guest Speakers
  • Insights
    • Tokens Talk
      • Community Discussions
      • Guest Posts
      • Opinion Pieces
    • Artificial Intelligence
      • AI in Blockchain
      • AI Security
      • AI Trading Bots
  • Learn
    • Projects
      • Ethereum
      • Solana
      • SUI
      • Memecoins
    • Educational
      • Beginner Guides
      • Advanced Strategies
      • Glossary Terms
No Result
View All Result
Crypto Endevr
  • Top Stories
    • Latest News
    • Trending
    • Editor’s Picks
  • Media
    • YouTube Videos
      • Interviews
      • Tutorials
      • Market Analysis
    • Podcasts
      • Latest Episodes
      • Featured Podcasts
      • Guest Speakers
  • Insights
    • Tokens Talk
      • Community Discussions
      • Guest Posts
      • Opinion Pieces
    • Artificial Intelligence
      • AI in Blockchain
      • AI Security
      • AI Trading Bots
  • Learn
    • Projects
      • Ethereum
      • Solana
      • SUI
      • Memecoins
    • Educational
      • Beginner Guides
      • Advanced Strategies
      • Glossary Terms
No Result
View All Result
Crypto Endevr
No Result
View All Result

Ivanti zero-day exploited by APT group that previously targeted Connect Secure appliances

Ivanti zero-day exploited by APT group that previously targeted Connect Secure appliances
Share on FacebookShare on Twitter

Chinese Cyberespionage Group Exploits Critical Remote Code Execution Vulnerability

Background

Researchers from Google’s Mandiant division have discovered that a critical remote code execution vulnerability, patched on Wednesday by software vendor Ivanti, has been exploited since mid-December by a Chinese cyberespionage group. This group has a history of exploiting zero-day vulnerabilities in Ivanti Connect Secure appliances, dating back to January 2024.

The Latest Attacks

The latest attacks, exploiting the new CVE-2025-0282 flaw, involved the deployment of multiple malware components from a toolkit dubbed SPAWN. Mandiant attributes this activity to a cluster of activity tracked as UNC5337, which is suspected to be related to another group tracked as UNC5221.

UNC5221: A Suspected China-Nexus Espionage Actor

UNC5221 is a suspected China-nexus espionage actor that has exploited vulnerabilities in Ivanti Connect Secure VPN and Ivanti Policy Security appliances as early as December 2023. Mandiant previously observed UNC5221 leveraging a likely ORB network of compromised Cyberoam appliances to enable intrusion operations.

The SPAWN Family of Malware Tools

The SPAWN family of custom malware tools includes the SPAWNANT installer, SPAWNMOLE tunneler, the SPAWNSNAIL SSH backdoor, and the SPAWNSLOTH log tampering utility. In addition to these known tools, the latest attacks also involved never-before-seen components, including a credential harvester dubbed DRYHOOK and a malware dropper called PHASEJAM.

Malware Prevents Legitimate Upgrades

In its security advisory, Ivanti directed customers to perform a factory reset on appliances before deploying the patched 22.7R2.5 version. Mandiant’s analysis suggests that this is because of the PHASEJAM dropper, which modifies multiple legitimate Connect Secure components, including the one responsible for system upgrades. PHASEJAM blocks and simulates upgrades in a visually convincing way, even displaying the new version number at the end of the process.

Conclusion

The exploitation of the CVE-2025-0282 flaw by a Chinese cyberespionage group highlights the importance of timely patching and security measures to prevent attacks. The use of custom malware tools and the ability to modify legitimate components to prevent upgrades demonstrate the sophistication and persistence of these attackers.

FAQs

Q: What is the CVE-2025-0282 flaw?

A: The CVE-2025-0282 flaw is a critical remote code execution vulnerability patched by Ivanti on Wednesday.

Q: Who is responsible for the exploitation of this flaw?

A: Researchers from Google’s Mandiant division believe that a Chinese cyberespionage group, tracked as UNC5337 and suspected to be related to UNC5221, is responsible for the exploitation of this flaw.

Q: What is the SPAWN family of malware tools?

A: The SPAWN family of custom malware tools includes the SPAWNANT installer, SPAWNMOLE tunneler, the SPAWNSNAIL SSH backdoor, and the SPAWNSLOTH log tampering utility, among others.

Q: Why did Ivanti recommend a factory reset on appliances before deploying the patched version?

A: Ivanti recommended a factory reset on appliances because of the PHASEJAM dropper, which modifies legitimate Connect Secure components to prevent upgrades.

Q: What can organizations do to prevent similar attacks?

A: Organizations can take steps to prevent similar attacks by ensuring timely patching, implementing robust security measures, and monitoring for suspicious activity.

cryptoendevr

cryptoendevr

Related Stories

Cisco Wireless LAN Controllers under threat again after critical exploit details go public

Cisco Wireless LAN Controllers under threat again after critical exploit details go public

June 3, 2025
0

Rewrite the According to the Horizon3 analysis, a hard-coded JSON Web Token (JWT) is at the root of the exploit....

Google patches third zero-day flaw in Chrome this year

Google patches third zero-day flaw in Chrome this year

June 3, 2025
0

Rewrite the Vulnerability in the JavaScript engine The Chrome team described the vulnerability as an out of bounds memory read...

One hacker, many names: Industry collaboration aims to fix cyber threat label chaos

One hacker, many names: Industry collaboration aims to fix cyber threat label chaos

June 3, 2025
0

Rewrite the The collaboration validates specific connections, such as confirming that CrowdStrike’s Vanguard Panda and Microsoft’s Volt Typhoon both represent...

The high cost of misconfigured DevOps: Global cryptojacking hits enterprises

The high cost of misconfigured DevOps: Global cryptojacking hits enterprises

June 3, 2025
0

Rewrite the Cloud workloads running these tools are especially at risk. Once compromised, attackers siphon off significant computing power, resulting...

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Bitcoin traders predict ‘larger correction’ as BTC price eyes sub-0K liquidity

Bitcoin traders predict ‘larger correction’ as BTC price eyes sub-$100K liquidity

June 3, 2025
Ripple RLUSD and Solana deals enhance Dubai crypto hub status

Ripple RLUSD and Solana deals enhance Dubai crypto hub status

June 3, 2025
Falschinformationen im Netz werden nur selten erkannt

Falschinformationen im Netz werden nur selten erkannt

June 3, 2025
Big Move Incoming For Bitcoin & Altcoins! [Top Entries]

Big Move Incoming For Bitcoin & Altcoins! [Top Entries]

June 3, 2025
Ethereum Foundation Restructures R&D Division, Plans ‘Rethink’ on Design and Development

Ethereum Foundation Restructures R&D Division, Plans ‘Rethink’ on Design and Development

June 3, 2025

Our Newsletter

Join TOKENS for a quick weekly digest of the best in crypto news, projects, posts, and videos for crypto knowledge and wisdom.

CRYPTO ENDEVR

About Us

Crypto Endevr aims to simplify the vast world of cryptocurrencies and blockchain technology for our readers by curating the most relevant and insightful articles from around the web. Whether you’re a seasoned investor or new to the crypto scene, our mission is to deliver a streamlined feed of news and analysis that keeps you informed and ahead of the curve.

Links

Home
Privacy Policy
Terms and Services

Resources

Glossary

Other

About Us
Contact Us

Our Newsletter

Join TOKENS for a quick weekly digest of the best in crypto news, projects, posts, and videos for crypto knowledge and wisdom.

© Copyright 2024. All Right Reserved By Crypto Endevr.

No Result
View All Result
  • Top Stories
    • Latest News
    • Trending
    • Editor’s Picks
  • Media
    • YouTube Videos
      • Interviews
      • Tutorials
      • Market Analysis
    • Podcasts
      • Latest Episodes
      • Featured Podcasts
      • Guest Speakers
  • Insights
    • Tokens Talk
      • Community Discussions
      • Guest Posts
      • Opinion Pieces
    • Artificial Intelligence
      • AI in Blockchain
      • AI Security
      • AI Trading Bots
  • Learn
    • Projects
      • Ethereum
      • Solana
      • SUI
      • Memecoins
    • Educational
      • Beginner Guides
      • Advanced Strategies
      • Glossary Terms

Copyright © 2024. All Right Reserved By Crypto Endevr