HomeSecurityIvanti Connect Secure: Mass exploitation of zero-day vulnerabilities

Ivanti Connect Secure: Mass exploitation of zero-day vulnerabilities

Two zero-day vulnerabilities affecting Ivanti's Connect Secure VPN and Policy Secure Network Access Control (NAC) appliances are being widely exploited in cyberattacks.

Ivanti Connect Secure

Researchers at Volexity, who were the first to spot the zero-days in December attacks, have now seen multiple hacking groups combining the authentication bypass vulnerability, CVE-2023-46805, and the command injection vulnerability, CVE-2024-21887, to carry out attacks. These new cyberattacks have been detected since January 11.

According to researchers, the attackers are targeting victims all over the world. The victims can be small businesses as well as some of the largest and most well-known organizations.

See also: Ivanti: Warns of critical vulnerability in EPM software

The attackers backdoored their targets' systems using a GIFTEDVISITOR webshell found on hundreds of devices.

“As of Sunday, January 14, 2024, Volexity had identified over 1,700 ICS VPN devices that had been compromised with the GIFFEDVISITOR webshell. These devices appear to have been targeted indiscriminately, with victims located all over the world,” Volexity said.

Investigators say victims include government and military agencies, national telecommunications companies, defense contractors, technology companies, banking organizations, consulting firms, and aerospace, aviation and engineering companies.

Ivanti has not yet released security updates for these two zero-day vulnerabilities, so administrators will need to take some other interim measures to protect ICS VPNs on their network.

They should also run Integrity Checker Tool and assume that all data on the ICS VPN device (including passwords and any secrets) has been compromised if any evidence of a breach is found.

See also: Ivanti patches critical vulnerabilities in Avalanche

Ivanti zero-day

Threat monitoring service Shadowserver has identified more than 16,800 ICS VPN devices exposed online, making them even more vulnerable.

As Ivanti revealed last week, attackers can execute commands on all supported versions of ICS VPN and IPS appliances when they successfully connect the two zero-day vulnerabilities.

The worrying thing is that attacks have now increased significantly. Many different groups are exploiting the vulnerabilities, targeting organizations all over the world.

According to Mandiant, at least five custom malware that are deployed on compromised customer systems, with the ultimate goal of installing web shells, additional malicious payloads, and stealing credentials.

The tools used in the attacks:

  • Zipline Passive Backdoor: can intercept network traffic, supports upload/download operations, creates reverse shells, proxy servers, server tunneling
  • Thinspool Dropper: this is a custom shell script dropper that writes the Lightwire web shell to Ivanti CS, ensuring persistence
  • Wirefire web shell: custom Python-based web shell that supports command execution and installs malicious payloads
  • Lightwire web shell: custom Perl web shell embedded in a legitimate file that allows execution of malicious commands
  • Warpwire harvester: custom JavaScript-based tool for collecting connection credentials and sending them to the attackers' command and control (C2) server
  • PySoxy tunneler: facilitates network traffic tunneling for privacy
  • BusyBox: multi-call binary that combines many Unix utilities
  • Thinspool utility (sessionserver.pl): used to restore the file system as "read/write" to enable malware deployment

How to protect yourself from Ivanti vulnerabilities

One of the most effective ways to protect yourself from vulnerability exploitation is to apply the latest security and patches (when released by Ivanti).

Additionally, using a robust intrusion detection software (IDS) or intrusion prevention system (IPS) can help detect and prevent zero-day exploitation attempts.

See also: Ivanti warns of a new MobileIron zero-day bug

Educating users on safe internet use and recognizing phishing attacks is also crucial. Phishing are a common tactic used by attackers to exploit zero-days.

Finally, using specialized vulnerability management software can help detect and prevent zero-day attacks. This software can continuously monitor the network for signs of attacks and provide alerts when it detects something suspicious.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS