McLellan, T. et al. (2024, January 12). Cutting Edge: Suspected APT Targets Ivanti Connect Secure VPN in New Zero-Day Exploitation. Retrieved February 27, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareWARPWIRE | WARPWIRE can send captured credentials to C2 via HTTP `GET` or `POST` requests. |
| T1056.003 Web Portal Capture |
MalwareWARPWIRE | WARPWIRE can capture credentials submitted during the web logon process in order to access layer seven applications such as RDP. |
| T1057 Process Discovery |
MalwareZIPLINE | ZIPLINE can identify running processes and their names. |
| T1059 Command and Scripting Interpreter |
CampaignCutting Edge | During Cutting Edge, threat actors used Perl scripts to enable the deployment of the THINSPOOL shell script dropper and for enumerating host data. |
| T1059.004 Unix Shell |
MalwareZIPLINE | ZIPLINE can use `/bin/sh` to create a reverse shell and execute commands. |
| T1059.007 JavaScript |
MalwareWARPWIRE | WARPWIRE is a credential harvester written in JavaScript. |
| T1071.001 Web Protocols |
MalwareWIREFIRE | WIREFIRE can respond to specific HTTP `POST` requests to `/api/v1/cav/client/visits`. |
| T1083 File and Directory Discovery |
MalwareZIPLINE | ZIPLINE can find and append specific files on Ivanti Connect Secure VPNs based upon received commands. |
| T1090 Proxy |
MalwareZIPLINE | ZIPLINE can create a proxy server on compromised hosts. |
| T1105 Ingress Tool Transfer |
MalwareZIPLINE | ZIPLINE can download files to be saved on the compromised system. |
| T1105 Ingress Tool Transfer |
MalwareWIREFIRE | WIREFIRE has the ability to download files to compromised devices. |
| T1132.001 Standard Encoding |
MalwareWARPWIRE | WARPWIRE can Base64 encode captured credentials with `btoa()` prior to sending to C2. |
| T1132.001 Standard Encoding |
MalwareWIREFIRE | WIREFIRE can Base64 encode process output sent to C2. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareWIREFIRE | WIREFIRE can decode, decrypt, and decompress data received in C2 HTTP `POST` requests. |
| T1190 Exploit Public-Facing Application |
CampaignCutting Edge | During Cutting Edge, threat actors exploited CVE-2023-46805 and CVE-2024-21887 in Ivanti Connect Secure VPN appliances to enable authentication bypass and command injection. A server-side request forgery (SSRF) vulnerability, CVE-2024-21893, was identified later and used to bypass mitigations for the initial two vulnerabilities by chaining with CVE-2024-21887. |
| T1205 Traffic Signaling |
MalwareZIPLINE | ZIPLINE can identify a specific string in intercepted network traffic, `SSH-2.0-OpenSSH_0.3xx.`, to trigger its command functionality. |
| T1505.003 Web Shell |
MalwareWIREFIRE | WIREFIRE is a web shell that can download files to and execute arbitrary commands from compromised Ivanti Connect Secure VPNs. |
| T1505.003 Web Shell |
CampaignCutting Edge | During Cutting Edge, threat actors used multiple web shells to maintain presence on compromised Connect Secure appliances such as WIREFIRE, GLASSTOKEN, BUSHWALK, LIGHTWIRE, and FRAMESTING. |
| T1554 Compromise Host Software Binary |
MalwareLIGHTWIRE | LIGHTWIRE can imbed itself into the legitimate `compcheckresult.cgi` component of Ivanti Connect Secure VPNs to enable command execution. |
| T1554 Compromise Host Software Binary |
MalwareWARPWIRE | WARPWIRE can embed itself into a legitimate file on compromised Ivanti Connect Secure VPNs. |
| T1554 Compromise Host Software Binary |
CampaignCutting Edge | During Cutting Edge, threat actors trojanized legitimate files in Ivanti Connect Secure appliances with malicious code. |
| T1554 Compromise Host Software Binary |
MalwareWIREFIRE | WIREFIRE can modify the `visits.py` component of Ivanti Connect Secure VPNs for file download and arbitrary command execution. |
| T1573.001 Symmetric Cryptography |
MalwareWIREFIRE | WIREFIRE can AES encrypt process output sent from compromised devices to C2. |
| T1584.008 Network Devices |
CampaignCutting Edge | During Cutting Edge, threat actors used compromised and out-of-support Cyberoam VPN appliances for C2. |
| T1588.002 Tool |
CampaignCutting Edge | During Cutting Edge, threat actors leveraged tools including Interactsh to identify vulnerable targets, PySoxy to simultaneously dispatch traffic between multiple endpoints, BusyBox to enable post exploitation activities, and Kubo Injector to inject shared objects into process memory. |
| T1685 Disable or Modify Tools |
MalwareZIPLINE | ZIPLINE can add itself to the exclusion list for the Ivanti Connect Secure Integrity Checker Tool if the `--exclude` parameter is passed by the `tar` process. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.