HomeSecurityExploiting vulnerabilities in Ivanti Connect Secure to distribute MetaRAT

Exploiting vulnerabilities in Ivanti Connect Secure to distribute MetaRAT

A new cyber campaign originating from China has come under the microscope of security researchers as it targets leading shipping and transportation companies in Japan. The attacks exploit critical vulnerabilities in Ivanti Connect Secure (ICS), allowing attackers to infiltrate corporate networks and install advanced malware.

Ivanti Connect Secure

Exploiting vulnerabilities for initial access

The campaign, which was revealed in April 2025, relies on two critical vulnerabilities — CVE-2024-21893 and CVE-2024-21887 — through which attackers gain initial foothold in ICS systems. Once they breach the network perimeter, they install multiple variants of the malicious PlugX, including the new MetaRAT and Talisman PlugX, which are capable of persistent presence and remote control.

See also: Apache Tika: Risk from vulnerability that was fixed months ago

From breach to espionage

Once they gain access, hackers conduct a thorough reconnaissance of the network, mapping critical structures and collecting credentials from compromised devices. Of particular value are the credentials of privileged Active Directory accounts, which allow them to move laterally and gradually take over internal servers.

In this way, they systematically install PlugX variants at multiple points in the network, ensuring the resilience of their campaign and the possibility of future espionage or sabotage operations. This multi-layered tactic reveals deep knowledge of corporate systems and extremely careful planning.

Exploiting vulnerabilities in Ivanti Connect Secure to distribute MetaRAT

Traces of the attack and finding the malware

LAC Watch experts identified traces of the campaign through forensic analysis of compromised Ivanti systems. Critical clues included logs with error code ERR31093 , which appear when ICS processes malicious SAML payloads — direct evidence of an exploit of CVE-2024-21893.

See also: Critical vulnerabilities in WatchGuard Firebox allow malicious code injection

The Integrity Check Tool also revealed suspicious files associated with known malware families, such as LITTLELAMB, WOOLTEA, PITSOCK, and PITFUEL. At the same time, the analysis led to the detection of MetaRAT, a modern variant of PlugX that, although released in 2022, had not been fully documented and analyzed until now.

How MetaRAT works

Researchers found that MetaRAT relies on DLL sideloading, leveraging legitimate Windows processes to activate malicious code without arousing suspicion. The mytilus3.dll acts as a launcher, loading an encrypted shellcode called “materoll.”

This is first decrypted via XOR (key 0xA6), executed in memory, and then triggers a new decryption stage based on AES-256-ECB. The final payload — the full MetaRAT — is compressed with LZNT1, making it even more difficult to analyze.

Signs of a breach and the need for immediate response

Organizations using vulnerable versions of Ivanti Connect Secure are urged to immediately available updates. At the same time, researchers warn that the detection of service entries with names such as “sihosts”, as well as registry keys with the label “matesile”, are potential indications of an active infection.

See also: Exploiting vulnerabilities in Sneeit WordPress and ICTBroadcast fuels Frost botnet

Additionally, the presence of keylog files such as “VniFile.hlp” in the %ALLUSERSPROFILE%\mates\ directory may indicate active surveillance of systems by attackers.

Exploiting vulnerabilities in Ivanti Connect Secure to distribute MetaRAT

A sector in the spotlight

The shipping industry has long been an attractive target for state-backed entities due to its strategic and economic importance. The new campaign highlights how vulnerable critical infrastructure can become when not updated in a timely manner or when relying on older systems.

As attacks become increasingly complex, organizations must strengthen their digital defenses, invest in detecting unusual behavior, and adopt strict identity and access management practices.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS