A new cyber campaign originating from China has come under the microscope of security researchers as it targets leading shipping and transportation companies in Japan. The attacks exploit critical vulnerabilities in Ivanti Connect Secure (ICS), allowing attackers to infiltrate corporate networks and install advanced malware.

Exploiting vulnerabilities for initial access
The campaign, which was revealed in April 2025, relies on two critical vulnerabilities — CVE-2024-21893 and CVE-2024-21887 — through which attackers gain initial foothold in ICS systems. Once they breach the network perimeter, they install multiple variants of the malicious PlugX, including the new MetaRAT and Talisman PlugX, which are capable of persistent presence and remote control.
See also: Apache Tika: Risk from vulnerability that was fixed months ago
From breach to espionage
Once they gain access, hackers conduct a thorough reconnaissance of the network, mapping critical structures and collecting credentials from compromised devices. Of particular value are the credentials of privileged Active Directory accounts, which allow them to move laterally and gradually take over internal servers.
In this way, they systematically install PlugX variants at multiple points in the network, ensuring the resilience of their campaign and the possibility of future espionage or sabotage operations. This multi-layered tactic reveals deep knowledge of corporate systems and extremely careful planning.

Traces of the attack and finding the malware
LAC Watch experts identified traces of the campaign through forensic analysis of compromised Ivanti systems. Critical clues included logs with error code ERR31093 , which appear when ICS processes malicious SAML payloads — direct evidence of an exploit of CVE-2024-21893.
See also: Critical vulnerabilities in WatchGuard Firebox allow malicious code injection
The Integrity Check Tool also revealed suspicious files associated with known malware families, such as LITTLELAMB, WOOLTEA, PITSOCK, and PITFUEL. At the same time, the analysis led to the detection of MetaRAT, a modern variant of PlugX that, although released in 2022, had not been fully documented and analyzed until now.
How MetaRAT works
Researchers found that MetaRAT relies on DLL sideloading, leveraging legitimate Windows processes to activate malicious code without arousing suspicion. The mytilus3.dll acts as a launcher, loading an encrypted shellcode called “materoll.”
This is first decrypted via XOR (key 0xA6), executed in memory, and then triggers a new decryption stage based on AES-256-ECB. The final payload — the full MetaRAT — is compressed with LZNT1, making it even more difficult to analyze.
Signs of a breach and the need for immediate response
Organizations using vulnerable versions of Ivanti Connect Secure are urged to immediately available updates. At the same time, researchers warn that the detection of service entries with names such as “sihosts”, as well as registry keys with the label “matesile”, are potential indications of an active infection.
See also: Exploiting vulnerabilities in Sneeit WordPress and ICTBroadcast fuels Frost botnet
Additionally, the presence of keylog files such as “VniFile.hlp” in the %ALLUSERSPROFILE%\mates\ directory may indicate active surveillance of systems by attackers.

A sector in the spotlight
The shipping industry has long been an attractive target for state-backed entities due to its strategic and economic importance. The new campaign highlights how vulnerable critical infrastructure can become when not updated in a timely manner or when relying on older systems.
As attacks become increasingly complex, organizations must strengthen their digital defenses, invest in detecting unusual behavior, and adopt strict identity and access management practices.
