Sunday, May 25, 2025
Homecyber securityHackers Exploit Ivanti Connect Secure 0-Day to Deploy DslogdRAT and Web Shell

Hackers Exploit Ivanti Connect Secure 0-Day to Deploy DslogdRAT and Web Shell

Published on

SIEM as a Service

Follow Us on Google News

Threat actors exploited a zero-day vulnerability in Ivanti Connect Secure, identified as CVE-2025-0282, to deploy malicious tools including a web shell and a sophisticated remote access trojan (RAT) named DslogdRAT.

According to a detailed analysis by JPCERT/CC, these attacks underscore the persistent and evolving risks surrounding Ivanti products, which have become a frequent target for cybercriminals.

The deployment of such malware through unpatched vulnerabilities highlights the critical need for organizations to prioritize timely updates and robust monitoring to mitigate potential breaches.

- Advertisement - Google News

The attackers initially installed a web shell written in Perl, which operates as a CGI script to process incoming HTTP requests.

 Ivanti Connect Secure
A part of the web shell

This script specifically checks for a hardcoded token in the Cookie header (DSAUTOKEN=af95380019083db5) and, upon validation, executes arbitrary commands passed through a request parameter.

Technical Breakdown of DslogdRAT and Web Shell Operations

This rudimentary yet effective backdoor likely served as the gateway for deploying DslogdRAT, a modular RAT with advanced capabilities.

Upon execution, DslogdRAT spawns a primary process that quickly terminates after creating a child process, which then decodes hardcoded configuration data using a simple XOR operation with the key 0x63.

 Ivanti Connect Secure
Execution Flow of DslogdRAT

This configuration dictates the malware’s operational window between 8:00 AM and 8:00 PM, presumably to blend in with regular business activity and evade detection.

A second child process handles core functionalities like establishing socket-based communication with a command-and-control (C2) server, where data is encoded via a 7-byte XOR scheme ranging from 0x01 to 0x07.

The malware transmits host-specific information during initial exchanges and supports commands for file uploads/downloads, shell command execution, and proxy operations, making it a versatile tool for persistent access.

Further compounding the threat, the same compromised systems revealed the presence of SPAWNSNARE, a malware previously documented by CISA and Google in April 2025.

While it remains unclear if these attacks tie directly to the UNC5221 group associated with the SPAWN family, the overlap suggests a potential broader campaign exploiting Ivanti vulnerabilities.

JPCERT/CC also noted an additional alert for CVE-2025-22457, signaling that Ivanti Connect Secure remains a high-value target for attackers.

The encoded configuration, communication patterns, and multi-threaded architecture using the pthread library in DslogdRAT demonstrate a deliberate design to maintain stealth and resilience on infected systems.

Organizations are urged to review indicators of compromise, such as C2 server details and file hashes provided in JPCERT/CC’s appendices, to detect and respond to these threats effectively.

As attacks on Ivanti infrastructure are expected to persist, proactive measures including patch management, network monitoring, and incident response planning are essential to safeguard critical systems from such sophisticated exploitation.

Find this News Interesting! Follow us on Google NewsLinkedIn, & X to Get Instant Updates!

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

Zero-Trust Policy Bypass Enables Exploitation of Vulnerabilities and Manipulation of NHI Secrets

A new project has exposed a critical attack vector that exploits protocol vulnerabilities to...

Threat Actor Sells Burger King Backup System RCE Vulnerability for $4,000

A threat actor known as #LongNight has reportedly put up for sale remote code...

Chinese Nexus Hackers Exploit Ivanti Endpoint Manager Mobile Vulnerability

Ivanti disclosed two critical vulnerabilities, identified as CVE-2025-4427 and CVE-2025-4428, affecting Ivanti Endpoint Manager...

Hackers Target macOS Users with Fake Ledger Apps to Deploy Malware

Hackers are increasingly targeting macOS users with malicious clones of Ledger Live, the popular...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Zero-Trust Policy Bypass Enables Exploitation of Vulnerabilities and Manipulation of NHI Secrets

A new project has exposed a critical attack vector that exploits protocol vulnerabilities to...

Threat Actor Sells Burger King Backup System RCE Vulnerability for $4,000

A threat actor known as #LongNight has reportedly put up for sale remote code...

Chinese Nexus Hackers Exploit Ivanti Endpoint Manager Mobile Vulnerability

Ivanti disclosed two critical vulnerabilities, identified as CVE-2025-4427 and CVE-2025-4428, affecting Ivanti Endpoint Manager...