Wednesday, May 7, 2025
Homecyber securityHackers Exploit Ivanti Connect Secure 0-Day to Deploy DslogdRAT and Web Shell

Hackers Exploit Ivanti Connect Secure 0-Day to Deploy DslogdRAT and Web Shell

Published on

SIEM as a Service

Follow Us on Google News

Threat actors exploited a zero-day vulnerability in Ivanti Connect Secure, identified as CVE-2025-0282, to deploy malicious tools including a web shell and a sophisticated remote access trojan (RAT) named DslogdRAT.

According to a detailed analysis by JPCERT/CC, these attacks underscore the persistent and evolving risks surrounding Ivanti products, which have become a frequent target for cybercriminals.

The deployment of such malware through unpatched vulnerabilities highlights the critical need for organizations to prioritize timely updates and robust monitoring to mitigate potential breaches.

- Advertisement - Google News

The attackers initially installed a web shell written in Perl, which operates as a CGI script to process incoming HTTP requests.

 Ivanti Connect Secure
A part of the web shell

This script specifically checks for a hardcoded token in the Cookie header (DSAUTOKEN=af95380019083db5) and, upon validation, executes arbitrary commands passed through a request parameter.

Technical Breakdown of DslogdRAT and Web Shell Operations

This rudimentary yet effective backdoor likely served as the gateway for deploying DslogdRAT, a modular RAT with advanced capabilities.

Upon execution, DslogdRAT spawns a primary process that quickly terminates after creating a child process, which then decodes hardcoded configuration data using a simple XOR operation with the key 0x63.

 Ivanti Connect Secure
Execution Flow of DslogdRAT

This configuration dictates the malware’s operational window between 8:00 AM and 8:00 PM, presumably to blend in with regular business activity and evade detection.

A second child process handles core functionalities like establishing socket-based communication with a command-and-control (C2) server, where data is encoded via a 7-byte XOR scheme ranging from 0x01 to 0x07.

The malware transmits host-specific information during initial exchanges and supports commands for file uploads/downloads, shell command execution, and proxy operations, making it a versatile tool for persistent access.

Further compounding the threat, the same compromised systems revealed the presence of SPAWNSNARE, a malware previously documented by CISA and Google in April 2025.

While it remains unclear if these attacks tie directly to the UNC5221 group associated with the SPAWN family, the overlap suggests a potential broader campaign exploiting Ivanti vulnerabilities.

JPCERT/CC also noted an additional alert for CVE-2025-22457, signaling that Ivanti Connect Secure remains a high-value target for attackers.

The encoded configuration, communication patterns, and multi-threaded architecture using the pthread library in DslogdRAT demonstrate a deliberate design to maintain stealth and resilience on infected systems.

Organizations are urged to review indicators of compromise, such as C2 server details and file hashes provided in JPCERT/CC’s appendices, to detect and respond to these threats effectively.

As attacks on Ivanti infrastructure are expected to persist, proactive measures including patch management, network monitoring, and incident response planning are essential to safeguard critical systems from such sophisticated exploitation.

Find this News Interesting! Follow us on Google NewsLinkedIn, & X to Get Instant Updates!

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

Top Ransomware Groups Target Financial Sector, 406 Incidents Revealed

Flashpoint analysts have reported that between April 2024 and April 2025, the financial sector...

Agenda Ransomware Group Enhances Tactics with SmokeLoader and NETXLOADER

The Agenda ransomware group, also known as Qilin, has been reported to intensify its...

SpyCloud Analysis Reveals 94% of Fortune 50 Companies Have Employee Data Exposed in Phishing Attacks

SpyCloud, the leading identity threat protection company, today released an analysis of nearly 6...

PoC Tool Released to Detect Servers Affected by Critical Apache Parquet Vulnerability

F5 Labs has released a new proof-of-concept (PoC) tool designed to help organizations detect...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Top Ransomware Groups Target Financial Sector, 406 Incidents Revealed

Flashpoint analysts have reported that between April 2024 and April 2025, the financial sector...

Agenda Ransomware Group Enhances Tactics with SmokeLoader and NETXLOADER

The Agenda ransomware group, also known as Qilin, has been reported to intensify its...

PoC Tool Released to Detect Servers Affected by Critical Apache Parquet Vulnerability

F5 Labs has released a new proof-of-concept (PoC) tool designed to help organizations detect...