ZIPLINE

S1114

Malware.View on attack.mitre.org

About this malware

ZIPLINE is a passive backdoor that was used during Cutting Edge on compromised Secure Connect VPNs for reverse shell and proxy functionality.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1057
Process Discovery

ZIPLINE can identify running processes and their names.

T1059.004
Unix Shell

ZIPLINE can use `/bin/sh` to create a reverse shell and execute commands.

T1083
File and Directory Discovery

ZIPLINE can find and append specific files on Ivanti Connect Secure VPNs based upon received commands.

T1090
Proxy

ZIPLINE can create a proxy server on compromised hosts.

T1095
Non-Application Layer Protocol

ZIPLINE can communicate with C2 using a custom binary protocol.

T1105
Ingress Tool Transfer

ZIPLINE can download files to be saved on the compromised system.

T1205
Traffic Signaling

ZIPLINE can identify a specific string in intercepted network traffic, `SSH-2.0-OpenSSH_0.3xx.`, to trigger its command functionality.

T1573.001
Symmetric Cryptography

ZIPLINE can use AES-128-CBC to encrypt data for both upload and download.

T1685
Disable or Modify Tools

ZIPLINE can add itself to the exclusion list for the Ivanti Connect Secure Integrity Checker Tool if the `--exclude` parameter is passed by the `tar` process.

Groups that use it0

None recorded.

Campaigns1

References1

  1. Mandiant Cutting Edge January 2024 Open source
    McLellan, T. et al. (2024, January 12). Cutting Edge: Suspected APT Targets Ivanti Connect Secure VPN in New Zero-Day Exploitation. Retrieved February 27, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.