ATT&CKCampaignsCutting Edge

Cutting Edge

C0029

Campaign, Dec 2023 to Feb 2024.View on attack.mitre.org

About this campaign

Cutting Edge was a campaign conducted by suspected China-nexus espionage actors, variously identified as UNC5221/UTA0178 and UNC5325, that began as early as December 2023 with the exploitation of zero-day vulnerabilities in Ivanti Connect Secure (previously Pulse Secure) VPN appliances. Cutting Edge targeted the U.S. defense industrial base and multiple sectors globally including telecommunications, financial, aerospace, and technology. Cutting Edge featured the use of defense evasion and living-off-the-land (LoTL) techniques along with the deployment of web shells and other custom malware.

Techniques used31

Procedure examples31

TechniqueProcedure example
T1003.001
LSASS Memory

During Cutting Edge, threat actors used Task Manager to dump LSASS memory from Windows devices to disk.

T1003.003
NTDS

During Cutting Edge, threat actors accessed and mounted virtual hard disk backups to extract
ntds.dit.

T1005
Data from Local System

During Cutting Edge, threat actors stole the running configuration and cache data from targeted Ivanti Connect Secure VPNs.

T1021.001
Remote Desktop Protocol

During Cutting Edge, threat actors used RDP with compromised credentials for lateral movement.

T1021.002
SMB/Windows Admin Shares

During Cutting Edge, threat actors moved laterally using compromised credentials to connect to internal Windows systems with SMB.

T1021.004
SSH

During Cutting Edge, threat actors used SSH for lateral movement.

T1027.013
Encrypted/Encoded File

During Cutting Edge, threat actors used a Base64-encoded Python script to write a patched version of the Ivanti Connect Secure `dsls` binary.

T1055
Process Injection

During Cutting Edge, threat actors used malicious SparkGateway plugins to inject shared objects into web process memory on compromised Ivanti Secure Connect VPNs to enable deployment of backdoors.

T1056.001
Keylogging

During Cutting Edge, threat actors modified a JavaScript file on the Web SSL VPN component of Ivanti Connect Secure devices to keylog credentials.

T1056.003
Web Portal Capture

During Cutting Edge, threat actors modified the JavaScript loaded by the Ivanti Connect Secure login page to capture credentials entered.

T1059
Command and Scripting Interpreter

During Cutting Edge, threat actors used Perl scripts to enable the deployment of the THINSPOOL shell script dropper and for enumerating host data.

T1059.006
Python

During Cutting Edge, threat actors used a Python reverse shell and the PySoxy SOCKS5 proxy tool.

T1070
Indicator Removal

During Cutting Edge, threat actors cleared logs to remove traces of their activity and restored compromised systems to a clean state to bypass manufacturer mitigations for CVE-2023-46805 and CVE-2024-21887.

T1070.004
File Deletion

During Cutting Edge, threat actors deleted `/tmp/test1.txt` on compromised Ivanti Connect Secure VPNs which was used to hold stolen configuration and cache files.

T1070.006
Timestomp

During Cutting Edge, threat actors changed timestamps of multiple files on compromised Ivanti Secure Connect VPNs to conceal malicious activity.

View all 31 procedure examples

Attributed groups0

MITRE does not attribute this campaign to a group.

Software11

References5

  1. Mandiant Cutting Edge January 2024 Open source
    McLellan, T. et al. (2024, January 12). Cutting Edge: Suspected APT Targets Ivanti Connect Secure VPN in New Zero-Day Exploitation. Retrieved February 27, 2024.
  2. Mandiant Cutting Edge Part 2 January 2024 Open source
    Lin, M. et al. (2024, January 31). Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation. Retrieved February 27, 2024.
  3. Mandiant Cutting Edge Part 3 February 2024 Open source
    Lin, M. et al. (2024, February 27). Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts. Retrieved March 1, 2024.
  4. Volexity Ivanti Global Exploitation January 2024 Open source
    Gurkok, C. et al. (2024, January 15). Ivanti Connect Secure VPN Exploitation Goes Global. Retrieved February 27, 2024.
  5. Volexity Ivanti Zero-Day Exploitation January 2024 Open source
    Meltzer, M. et al. (2024, January 10). Active Exploitation of Two Zero-Day Vulnerabilities in Ivanti Connect Secure VPN. Retrieved February 27, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.