John Wolfram, Josh Murchie, Matt Lin, Daniel Ainsworth, Robert Wallace, Dimiter Andonov, Dhanesh Kizhakkinan, Jacob Thompson. (2025, January 8). Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation. Retrieved April 14, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
MalwarePHASEJAM | PHASEJAM has encoded commands with Base64. |
| T1027.013 Encrypted/Encoded File |
MalwareDRYHOOK | DRYHOOK has encrypted stolen credentials strings within a file using both Base64 and RC4 with a hard-coded key. |
| T1027.013 Encrypted/Encoded File |
MalwarePHASEJAM | PHASEJAM has launched a webshell using the `MIME::Base64` module that encoded and decoded Base64 commands. |
| T1036.003 Rename Legitimate Utilities |
MalwarePHASEJAM | PHASEJAM has renamed the file `/home/bin/remotedebug` to `remotedebug.bak`, allowing the threats actors to write a malicious `/home/bin/remotedebug` shell script. |
| T1040 Network Sniffing |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has monitored and filtered network traffic on compromised edge devices, allowing legitimate traffic to pass while redirecting attacker-controlled traffic to infrastructure under adversary control. |
| T1041 Exfiltration Over C2 Channel |
MalwarePHASEJAM | PHASEJAM has the ability to exfiltrate data from the victim appliance. |
| T1056.001 Keylogging |
MalwareDRYHOOK | DRYHOOK has captured user credentials and passwords in plaintext and has encrypted them in a stored file on the network device. |
| T1059.006 Python |
MalwareDRYHOOK | DRYHOOK is a Python-based script that executes within the victim environment. |
| T1059.008 Network Device CLI |
MalwareDRYHOOK | DRYHOOK has the ability to interact with Ivanti Connect Secure environments and to modify system components. |
| T1059.008 Network Device CLI |
MalwarePHASEJAM | PHASEJAM has leveraged native commands associated with the compromised network appliance to execute code. |
| T1074.001 Local Data Staging |
MalwareDRYHOOK | DRYHOOK has stored stolen credentials for future use in the temp folder of a victimized Ivanti Connect Secure VPN device, specifically in the file location `/tmp/cmmmap.kumMW`. |
| T1105 Ingress Tool Transfer |
MalwarePHASEJAM | PHASEJAM has the ability to upload files onto the compromised appliance. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePHASEJAM | PHASEJAM has the ability to decode Base64 commands and data. |
| T1222.002 Linux and Mac Permissions |
MalwareDRYHOOK | DRYHOOK has the ability to remount the filesystem as “read-write” to make changes and then restores it to “read-only” prior to killing processes to apply the modifications. |
| T1489 Service Stop |
MalwarePHASEJAM | PHASEJAM has disabled the `cgi-server` process on Ivanti Connect Secure appliances. |
| T1489 Service Stop |
MalwareDRYHOOK | DRYHOOK has terminated all instances of the `cgi-server` process before activating the modified DSAuth.pm file. |
| T1505.003 Web Shell |
MalwarePHASEJAM | PHASEJAM has inserted Perl-based web shells into legitimate files that provided threat actors with remote access and code execution capabilities on the compromised network appliance. |
| T1546.004 Unix Shell Configuration Modification |
MalwarePHASEJAM | PHASEJAM has used a bash script to modify components on Ivanti Connect Secure appliances and execute files via `/bin/bash`.[1] It has also used the Linux stream editor (`sed`) to execute commands. |
| T1553.002 Code Signing |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has generated RSA keys against modified files to sign the manifest file, so they appear legitimate. |
| T1554 Compromise Host Software Binary |
MalwarePHASEJAM | PHASEJAM has modified legitimate components to enable persistence and execution, including inserting a web shell into `getComponent.cgi` and `restAuth.cgi`, modifying `DSUpgrade.pm` to block system upgrades, and overwriting `remotedebug` to execute arbitrary commands when specific parameters are provided. |
| T1556 Modify Authentication Process |
MalwareDRYHOOK | DRYHOOK has intercepted and logged user credentials by modifying the Perl module in Ivanti Connect Secure VPN edge-devices located within `/home/perl/DSAuth.pm`. |
| T1556.004 Network Device Authentication |
MalwareDRYHOOK | DRYHOOK has patched victim appliances authentication routines to capture credentials in plaintext as users log in. |
| T1565 Data Manipulation |
MalwarePHASEJAM | PHASEJAM has blocked legitimate upgrades of Ivanti Connect Secure systems and falsely indicates a successful upgrade while operating on an older version. |
| T1572 Protocol Tunneling |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has created SSH tunnels to facilitate C2 communications. |
| T1574 Hijack Execution Flow |
MalwareSPAWNCHIMERA | SPAWNCHIMERA can persist across system upgrades by hijacking the execution flow of dspkginstall, a binary used during the system upgrade process. |
| T1601 Modify System Image |
MalwareDRYHOOK | DRYHOOK has modified the Ivanti Connect Secure VPN authentication Perl module `DSAuth.pm` by reading its contents in the buffer, then finding and replacing select lines of code. |
| T1678 Delay Execution |
MalwarePHASEJAM | PHASEJAM has used the `sleep` command within its code to generate a fake HTML upgrade progress bar that mimics a running process. |
| T1685 Disable or Modify Tools |
MalwareDRYHOOK | DRYHOOK has killed all instances of the `cgi-server` process in order for the modified Perl module to be activated. |
| T1685 Disable or Modify Tools |
MalwarePHASEJAM | PHASEJAM has modified Ivanti Connect Secure appliances and blocks the system upgrades by altering the DSUpgrade.pm file. |
| T1685.003 Modify or Spoof Tool UI |
MalwarePHASEJAM | PHASEJAM has prevented legitimate Ivanti Connect Secure system upgrades by intercepting the upgrade command and rendering fake HTML upgrade progress bar through a function called `processUpgradeDisplay()` which allowed the compromised device to remain under the control of the adversary. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.