ATT&CKReferencesVolexity Ivanti Zero-Day Exploitation January 2024

Volexity Ivanti Zero-Day Exploitation January 2024

Meltzer, M. et al. (2024, January 10). Active Exploitation of Two Zero-Day Vulnerabilities in Ivanti Connect Secure VPN. Retrieved February 27, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns1

Procedure examples23

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
CampaignCutting Edge

During Cutting Edge, threat actors used Task Manager to dump LSASS memory from Windows devices to disk.

T1003.003
NTDS
CampaignCutting Edge

During Cutting Edge, threat actors accessed and mounted virtual hard disk backups to extract
ntds.dit.

T1005
Data from Local System
CampaignCutting Edge

During Cutting Edge, threat actors stole the running configuration and cache data from targeted Ivanti Connect Secure VPNs.

T1021.001
Remote Desktop Protocol
CampaignCutting Edge

During Cutting Edge, threat actors used RDP with compromised credentials for lateral movement.

T1021.002
SMB/Windows Admin Shares
CampaignCutting Edge

During Cutting Edge, threat actors moved laterally using compromised credentials to connect to internal Windows systems with SMB.

T1021.004
SSH
CampaignCutting Edge

During Cutting Edge, threat actors used SSH for lateral movement.

T1056.001
Keylogging
CampaignCutting Edge

During Cutting Edge, threat actors modified a JavaScript file on the Web SSL VPN component of Ivanti Connect Secure devices to keylog credentials.

T1056.003
Web Portal Capture
CampaignCutting Edge

During Cutting Edge, threat actors modified the JavaScript loaded by the Ivanti Connect Secure login page to capture credentials entered.

T1059.001
PowerShell
MalwareGLASSTOKEN

GLASSTOKEN can use PowerShell for command execution.

T1059.006
Python
CampaignCutting Edge

During Cutting Edge, threat actors used a Python reverse shell and the PySoxy SOCKS5 proxy tool.

T1070
Indicator Removal
CampaignCutting Edge

During Cutting Edge, threat actors cleared logs to remove traces of their activity and restored compromised systems to a clean state to bypass manufacturer mitigations for CVE-2023-46805 and CVE-2024-21887.

T1071.001
Web Protocols
MalwareWIREFIRE

WIREFIRE can respond to specific HTTP `POST` requests to `/api/v1/cav/client/visits`.

T1078.002
Domain Accounts
CampaignCutting Edge

During Cutting Edge, threat actors used compromised VPN accounts for lateral movement on targeted networks.

T1105
Ingress Tool Transfer
CampaignCutting Edge

During Cutting Edge, threat actors leveraged exploits to download remote files to Ivanti Connect Secure VPNs.

T1132.001
Standard Encoding
MalwareGLASSTOKEN

GLASSTOKEN has hexadecimal and Base64 encoded C2 content.

T1140
Deobfuscate/Decode Files or Information
MalwareGLASSTOKEN

GLASSTOKEN has the ability to decode hexadecimal and Base64 C2 requests.

T1190
Exploit Public-Facing Application
CampaignCutting Edge

During Cutting Edge, threat actors exploited CVE-2023-46805 and CVE-2024-21887 in Ivanti Connect Secure VPN appliances to enable authentication bypass and command injection. A server-side request forgery (SSRF) vulnerability, CVE-2024-21893, was identified later and used to bypass mitigations for the initial two vulnerabilities by chaining with CVE-2024-21887.

T1505.003
Web Shell
MalwareGLASSTOKEN

GLASSTOKEN is a web shell capable of tunneling C2 connections and code execution on compromised Ivanti Secure Connect VPNs.

T1505.003
Web Shell
CampaignCutting Edge

During Cutting Edge, threat actors used multiple web shells to maintain presence on compromised Connect Secure appliances such as WIREFIRE, GLASSTOKEN, BUSHWALK, LIGHTWIRE, and FRAMESTING.

T1554
Compromise Host Software Binary
CampaignCutting Edge

During Cutting Edge, threat actors trojanized legitimate files in Ivanti Connect Secure appliances with malicious code.

T1554
Compromise Host Software Binary
MalwareWIREFIRE

WIREFIRE can modify the `visits.py` component of Ivanti Connect Secure VPNs for file download and arbitrary command execution.

T1594
Search Victim-Owned Websites
CampaignCutting Edge

During Cutting Edge, threat actors peformed reconnaissance of victims' internal websites via proxied connections.

T1685
Disable or Modify Tools
CampaignCutting Edge

During Cutting Edge, threat actors disabled logging and modified the `compcheckresult.cgi` component to edit the Ivanti Connect Secure built-in Integrity Checker exclusion list to evade detection.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.