A significant percentage of exploitation attempts targeting a recently disclosed security vulnerability in Ivanti Endpoint Manager Mobile (EPMM) can be traced to a single IP address on bulletproof hosting infrastructure offered by PROSPERO.
See also: Ivanti patches vulnerabilities in Endpoint Manager (EPM)

Threat firm GreyNoise recorded 417 exploit sessions from 8 unique IP sources between February 1 and 9, 2026. It is estimated that 346 exploit sessions originated from 193.24.123[.]42, representing 83% of all attempts.
The malicious activity is designed to exploit CVE-2026-1281 (CVSS score: 9.8), one of two critical security vulnerabilities in EPMM, along with CVE-2026-1340, that an attacker could exploit to achieve unauthorized remote code execution. Last month, Ivanti acknowledged that it was aware of a “very limited number of customers” affected after these issues were exploited.
Since then, several European agencies, including the Dutch Data Protection Authority (AP), the Council of Justice, the European Commission, and Finland's Valtori, have revealed that they were targeted by unknown attackers who exploited the vulnerabilities.
Further analysis revealed that the same host is simultaneously exploiting three other CVEs in unrelated software:
- CVE-2026-21962 (Oracle WebLogic) – 2,902 sessions
- CVE-2026-24061 (GNU InetUtils telnetd) – 497 sessions
- CVE-2025-24799 (GLPI) – 200 sessions
See also: Dutch authorities confirm Ivanti zero-day exploit

It is worth noting that PROSPERO is believed to be linked to another autonomous system called Proton66, which has a history of distributing desktop and Android malware such as GootLoader, Matanbuchus, SpyNote, Coper (also known as Octo) , and SocGholish.
GreyNoise also pointed out that 85% of exploit sessions sent a signal through the domain name system (DNS) to confirm “that this target is exploitable” without deploying malware or extracting data.
The revelation comes just days after Defused Cyber reported on a “ sleeper shell ” campaign that deployed a dormant Java class loader in memory on compromised EPMM instances at the path “ /mifs/403.jsp .” The cybersecurity firm said the activity is indicative of the early access technique, where attackers establish a foothold to sell or transfer access later for financial gain.
“This pattern is significant,” he noted. “The OAST [out-of-band application security testing] calls indicate that the campaign is cataloging which targets are vulnerable rather than deploying payloads immediately. This is consistent with initial access operations verifying exploitability first and deploying monitoring tools later.”
Ivanti EPMM users are advised to apply the updates, check their Mobile Device Management (MDM) infrastructure exposed to the internet, review DNS logs for OAST pattern calls, monitor the /mifs/403.jsp path in EPMM instances, and block the PROSPERO autonomous system (AS200593) at the perimeter network level.
See also: Ivanti EPMM: Exploiting zero-day vulnerabilities – UPDATE NOW

“The EPMM breach provides access to the device management infrastructure for entire organizations, creating a lateral movement platform that bypasses traditional network segmentation,” GreyNoise said. “Organizations with MDM, VPN concentrators, or other remote access infrastructure exposed to the internet should operate on the assumption that critical vulnerabilities are exploited within hours of disclosure.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
