Cybersecurity experts are sounding the alarm over the emergence of a new malware called DslogdRAT, which installs itself on target machines after exploiting a vulnerability in Ivanti Connect Secure (now patched).

According to analysis by Yuma Masubuchi, a researcher at JPCERT/CC, the malware and an accompanying web shell were installed via the exploitation of the then-unknown zero-day vulnerability CVE-2025-0282. It targeted organizations in Japan around December 2024.
The vulnerability was a serious vulnerability in Ivanti Connect Secure that could allow attackers to execute arbitrary code remotely, without authorization. Ivanti released an update in January 2025.
See also: SAP fixes critical flaws in NetWeaver
However, before the update was released, the vulnerability had already been exploited by the cyberespionage group UNC5337, which is reportedly linked to China. The group used the vulnerability to distribute the SPAWN, along with other advanced tools.
Since then, both JPCERT/CC and the US Cybersecurity and Infrastructure Security Administration (CISA) have confirmed that the same vulnerability was exploited to install new variants of SPAWN, known as SPAWNCHIMERA and RESURGE.
Earlier this month, Mandiant revealed that a different vulnerability in Ivanti Connect Secure (CVE-2025-22457) was also used to distribute malware. This attack is attributed to another Chinese cyberespionage group, called UNC5221.
JPCERT /CC clarified that at present there is no clear evidence to indicate whether the attacks involving the DslogdRAT malware are related to the same campaign involving the well-known malware family SPAWN and the UNC5221 group .
See also: ASUS fixes AMI vulnerability that allows server compromise
The attack appears to begin by exploiting the CVE-2025-0282, which installs a web shell written in Perl. This tool paves the way for the installation of additional malware, including DslogdRAT.
Once installed, the DslogdRAT malware establishes a connection to a remote server and sends basic data about the target system . From there, it awaits instructions from the attacker, which allow it to execute shell commands, upload and download files, and use the compromised machine as a proxy for other attacks.

Malware protection
Static detection methods for security are not enough to avoid malware. A more robust approach should incorporate software antivirus, equipped with advanced analysis capabilities.
Information security training is also crucial. This means employees need to learn to recognize and avoid phishing attacks, which attackers often use to install malware.
It's also important to keep your operating system and applications up to date. These updates often include security patches that can protect your computer from the latest threats.
See also: Vulnerability in Active! Mail used for attacks in Japan
Also, don't forget to use firewalls and monitor network traffic to help immediately detect suspicious activity. Users are also advised to avoid executable files downloaded from strange websites.
Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection against malware. This can make it harder for attackers to gain access to your account , even if they manage to steal your password.
Source: thehackernews.com
