HomeSecurityCISA: RESURGE malware remains dormant on Ivanti Connect Secure devices

CISA: RESURGE malware remains dormant on Ivanti Connect Secure devices

The latest update on the RESURGE malware from the Cybersecurity and Infrastructure Security Agency (CISA) points to a concerning reality for network defenders: the stealth-focused malware is becoming harder to detect and easier to persist within enterprise infrastructure.

See also: CISA in a difficult situation due to cuts and layoffs

RESURGE
CISA: RESURGE malware remains dormant on Ivanti Connect Secure devices

In its updated CISA malware analysis report, the agency revealed that malware can lie dormant for long periods on compromised Ivanti Connect Secure, only activating when attackers attempt to gain remote access. This dormant behavior increases the level of risk, as organizations may believe their systems are clean while the threat remains quietly embedded in the network.

The updated findings are based on the initial March 2025 report, but introduce deeper technical knowledge about how the RESURGE malware leverages advanced encryption, forged certificates, and Secure Shell (SSH) tunnels to maintain covert command and control communication.

According to the updated analysis, the malware is designed to exploit the Ivanti Connect Secure vulnerability CVE-2025-0282 and establish persistence through network-level evasion techniques.

In contrast to traditional malware that triggers alerts through continuous activity, this network avoidance malware remains dormant until a remote actor connects to the compromised device. This tactic allows it to bypass typical monitoring tools that largely rely on behavior detection.

CISA noted that the malware modifies files, handles integrity checks and deploys web shells directly on the Ivanti boot disk—methods that make removal more complex and detection less straightforward.

See also: CISA: FileZen vulnerability in the KEV Catalog

CISA: RESURGE malware remains dormant on Ivanti Connect Secure devices
CISA: RESURGE malware remains dormant on Ivanti Connect Secure devices

The emphasis on critical infrastructure underscores why the malicious software RESURGE is not merely another case of vulnerability exploitation—it represents a tool for persistent access that attackers can reuse over time. One of the most concerning elements of the updated malware analysis is the use of advanced cryptographic techniques and forged Transport Layer Security (TLS) certificates.

The CISA revealed that the malicious software uses the Elliptic Curve Cryptography (ECC) together with fake TLS certificates not just for encryption but for authentication—allowing attackers to verify that they are communicating with an infected device instead of a legitimate server. This approach makes the malicious SSH command-and-control software much harder to detect using traditional inspection tools.

The report also identified TLS fingerprint mechanisms and CRC32 hashing mechanisms that help malware distinguish between benign and malicious traffic. These multi-layered techniques show a clear shift towards malware design that prioritizes secrecy.

The updated RESURGE malware report reflects a broader trend in modern cyber threats: attackers prioritize persistence over immediate impact. Rather than launching noisy attacks, malicious actors embed long-term access mechanisms into network infrastructure.

The findings of CISA also reinforce the importance of proactively applying updates and threat hunting, especially for organizations using remote access devices such as Ivanti Connect Secure.

Another key takeaway is that relying solely on automated scanning tools is no longer sufficient. Dormant malware, by its nature, evades detection until it is too late.

See also: CISA: Federal agencies must fix Dell security flaw within 3 days

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

CISA: RESURGE malware remains dormant on Ivanti Connect Secure devices
CISA: RESURGE malware remains dormant on Ivanti Connect Secure devices

CISA has urged organizations to implement mitigation guidelines associated with CVE-2025-0282 and to use updated compromise indicators to detect possible infections.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS