ATT&CKReferencesGoogle UNC5221 Ivanti January 2025

Google UNC5221 Ivanti January 2025

John Wolfram, Josh Murchie, Matt Lin, Daniel Ainsworth, Robert Wallace, Dimiter Andonov, Dhanesh Kizhakkinan, Jacob Thompson. (2025, January 8). Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation. Retrieved April 14, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software3

Campaigns0

None recorded.

Procedure examples30

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
MalwarePHASEJAM

PHASEJAM has encoded commands with Base64.

T1027.013
Encrypted/Encoded File
MalwareDRYHOOK

DRYHOOK has encrypted stolen credentials strings within a file using both Base64 and RC4 with a hard-coded key.

T1027.013
Encrypted/Encoded File
MalwarePHASEJAM

PHASEJAM has launched a webshell using the `MIME::Base64` module that encoded and decoded Base64 commands.

T1036.003
Rename Legitimate Utilities
MalwarePHASEJAM

PHASEJAM has renamed the file `/home/bin/remotedebug` to `remotedebug.bak`, allowing the threats actors to write a malicious `/home/bin/remotedebug` shell script.

T1040
Network Sniffing
MalwareSPAWNCHIMERA

SPAWNCHIMERA has monitored and filtered network traffic on compromised edge devices, allowing legitimate traffic to pass while redirecting attacker-controlled traffic to infrastructure under adversary control.

T1041
Exfiltration Over C2 Channel
MalwarePHASEJAM

PHASEJAM has the ability to exfiltrate data from the victim appliance.

T1056.001
Keylogging
MalwareDRYHOOK

DRYHOOK has captured user credentials and passwords in plaintext and has encrypted them in a stored file on the network device.

T1059.006
Python
MalwareDRYHOOK

DRYHOOK is a Python-based script that executes within the victim environment.

T1059.008
Network Device CLI
MalwareDRYHOOK

DRYHOOK has the ability to interact with Ivanti Connect Secure environments and to modify system components.

T1059.008
Network Device CLI
MalwarePHASEJAM

PHASEJAM has leveraged native commands associated with the compromised network appliance to execute code.

T1074.001
Local Data Staging
MalwareDRYHOOK

DRYHOOK has stored stolen credentials for future use in the temp folder of a victimized Ivanti Connect Secure VPN device, specifically in the file location `/tmp/cmmmap.kumMW`.

T1105
Ingress Tool Transfer
MalwarePHASEJAM

PHASEJAM has the ability to upload files onto the compromised appliance.

T1140
Deobfuscate/Decode Files or Information
MalwarePHASEJAM

PHASEJAM has the ability to decode Base64 commands and data.

T1222.002
Linux and Mac Permissions
MalwareDRYHOOK

DRYHOOK has the ability to remount the filesystem as “read-write” to make changes and then restores it to “read-only” prior to killing processes to apply the modifications.

T1489
Service Stop
MalwarePHASEJAM

PHASEJAM has disabled the `cgi-server` process on Ivanti Connect Secure appliances.

T1489
Service Stop
MalwareDRYHOOK

DRYHOOK has terminated all instances of the `cgi-server` process before activating the modified DSAuth.pm file.

T1505.003
Web Shell
MalwarePHASEJAM

PHASEJAM has inserted Perl-based web shells into legitimate files that provided threat actors with remote access and code execution capabilities on the compromised network appliance.

T1546.004
Unix Shell Configuration Modification
MalwarePHASEJAM

PHASEJAM has used a bash script to modify components on Ivanti Connect Secure appliances and execute files via `/bin/bash`.[1] It has also used the Linux stream editor (`sed`) to execute commands.

T1553.002
Code Signing
MalwareSPAWNCHIMERA

SPAWNCHIMERA has generated RSA keys against modified files to sign the manifest file, so they appear legitimate.

T1554
Compromise Host Software Binary
MalwarePHASEJAM

PHASEJAM has modified legitimate components to enable persistence and execution, including inserting a web shell into `getComponent.cgi` and `restAuth.cgi`, modifying `DSUpgrade.pm` to block system upgrades, and overwriting `remotedebug` to execute arbitrary commands when specific parameters are provided.

T1556
Modify Authentication Process
MalwareDRYHOOK

DRYHOOK has intercepted and logged user credentials by modifying the Perl module in Ivanti Connect Secure VPN edge-devices located within `/home/perl/DSAuth.pm`.

T1556.004
Network Device Authentication
MalwareDRYHOOK

DRYHOOK has patched victim appliances authentication routines to capture credentials in plaintext as users log in.

T1565
Data Manipulation
MalwarePHASEJAM

PHASEJAM has blocked legitimate upgrades of Ivanti Connect Secure systems and falsely indicates a successful upgrade while operating on an older version.

T1572
Protocol Tunneling
MalwareSPAWNCHIMERA

SPAWNCHIMERA has created SSH tunnels to facilitate C2 communications.

T1574
Hijack Execution Flow
MalwareSPAWNCHIMERA

SPAWNCHIMERA can persist across system upgrades by hijacking the execution flow of dspkginstall, a binary used during the system upgrade process.

T1601
Modify System Image
MalwareDRYHOOK

DRYHOOK has modified the Ivanti Connect Secure VPN authentication Perl module `DSAuth.pm` by reading its contents in the buffer, then finding and replacing select lines of code.

T1678
Delay Execution
MalwarePHASEJAM

PHASEJAM has used the `sleep` command within its code to generate a fake HTML upgrade progress bar that mimics a running process.

T1685
Disable or Modify Tools
MalwareDRYHOOK

DRYHOOK has killed all instances of the `cgi-server` process in order for the modified Perl module to be activated.

T1685
Disable or Modify Tools
MalwarePHASEJAM

PHASEJAM has modified Ivanti Connect Secure appliances and blocks the system upgrades by altering the DSUpgrade.pm file.

T1685.003
Modify or Spoof Tool UI
MalwarePHASEJAM

PHASEJAM has prevented legitimate Ivanti Connect Secure system upgrades by intercepting the upgrade command and rendering fake HTML upgrade progress bar through a function called `processUpgradeDisplay()` which allowed the compromised device to remain under the control of the adversary.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.