Lin, M. et al. (2024, February 27). Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts. Retrieved March 1, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1055 Process Injection |
CampaignCutting Edge | During Cutting Edge, threat actors used malicious SparkGateway plugins to inject shared objects into web process memory on compromised Ivanti Secure Connect VPNs to enable deployment of backdoors. |
| T1059.004 Unix Shell |
MalwarePITSTOP | PITSTOP has the ability to receive shell commands over a Unix domain socket. |
| T1059.006 Python |
CampaignCutting Edge | During Cutting Edge, threat actors used a Python reverse shell and the PySoxy SOCKS5 proxy tool. |
| T1070.004 File Deletion |
CampaignCutting Edge | During Cutting Edge, threat actors deleted `/tmp/test1.txt` on compromised Ivanti Connect Secure VPNs which was used to hold stolen configuration and cache files. |
| T1070.006 Timestomp |
CampaignCutting Edge | During Cutting Edge, threat actors changed timestamps of multiple files on compromised Ivanti Secure Connect VPNs to conceal malicious activity. |
| T1082 System Information Discovery |
MalwareLITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA can check the type of Ivanti VPN device it is running on by executing `first_run()` to identify the first four bytes of the motherboard serial number. |
| T1083 File and Directory Discovery |
MalwareLITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA can monitor for system upgrade events by checking for the presence of `/tmp/data/root/dev`. |
| T1090 Proxy |
MalwareLITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA has the ability to function as a SOCKS proxy. |
| T1095 Non-Application Layer Protocol |
MalwareLITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA can function as a stand-alone backdoor communicating over the `/tmp/clientsDownload.sock` socket. |
| T1095 Non-Application Layer Protocol |
CampaignCutting Edge | During Cutting Edge, threat actors used the Unix socket and a reverse TCP shell for C2 communications. |
| T1105 Ingress Tool Transfer |
MalwareBUSHWALK | BUSHWALK can write malicious payloads sent through a web request’s command parameter. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBUSHWALK | BUSHWALK can Base64 decode and RC4 decrypt malicious payloads sent through a web request’s command parameter. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePITSTOP | PITSTOP can deobfuscate base64 encoded and AES encrypted commands. |
| T1190 Exploit Public-Facing Application |
CampaignCutting Edge | During Cutting Edge, threat actors exploited CVE-2023-46805 and CVE-2024-21887 in Ivanti Connect Secure VPN appliances to enable authentication bypass and command injection. A server-side request forgery (SSRF) vulnerability, CVE-2024-21893, was identified later and used to bypass mitigations for the initial two vulnerabilities by chaining with CVE-2024-21887. |
| T1205 Traffic Signaling |
CampaignCutting Edge | During Cutting Edge, threat actors sent a magic 48-byte sequence to enable the PITSOCK backdoor to communicate via the `/tmp/clientsDownload.sock` socket. |
| T1205 Traffic Signaling |
MalwareBUSHWALK | BUSHWALK can modify the `DSUserAgentCap.pm` Perl module on Ivanti Connect Secure VPNs and either activate or deactivate depending on the value of the user agent in incoming HTTP requests. |
| T1205.002 Socket Filters |
MalwarePITSTOP | PITSTOP can listen and evaluate incoming commands on the domain socket, created by PITHOOK malware, located at `/data/runtime/cockpit/wd.fd` for a predefined magic byte sequence. PITSTOP can then duplicate the socket for further communication over TLS. |
| T1543 Create or Modify System Process |
MalwareLITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA can initialize itself as a daemon to run persistently in the background. |
| T1554 Compromise Host Software Binary |
MalwareLITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA can append malicious components to the `tmp/tmpmnt/bin/samba_upgrade.tar` archive inside the factory reset partition in attempt to persist post reset. |
| T1554 Compromise Host Software Binary |
MalwareBUSHWALK | BUSHWALK can embed into the legitimate `querymanifest.cgi` file on compromised Ivanti Connect Secure VPNs. |
| T1559 Inter-Process Communication |
MalwarePITSTOP | PITSTOP can listen over the Unix domain socket located at `/data/runtime/cockpit/wd.fd`. |
| T1573.002 Asymmetric Cryptography |
MalwarePITSTOP | PITSTOP has the ability to communicate over TLS. |
| T1573.002 Asymmetric Cryptography |
MalwareLITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA can communicate over SSL using the private key from the Ivanti Connect Secure web server. |
| T1588.002 Tool |
CampaignCutting Edge | During Cutting Edge, threat actors leveraged tools including Interactsh to identify vulnerable targets, PySoxy to simultaneously dispatch traffic between multiple endpoints, BusyBox to enable post exploitation activities, and Kubo Injector to inject shared objects into process memory. |
| T1595.002 Vulnerability Scanning |
CampaignCutting Edge | During Cutting Edge, threat actors used the publicly available Interactsh tool to identify Ivanti Connect Secure VPNs vulnerable to CVE-2024-21893. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.