WIREFIRE

S1115

Malware.View on attack.mitre.org

About this malware

WIREFIRE is a web shell written in Python that exists as trojanized logic to the visits.py component of Ivanti Connect Secure VPN appliances. WIREFIRE was used during Cutting Edge for downloading files and command execution.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1071.001
Web Protocols

WIREFIRE can respond to specific HTTP `POST` requests to `/api/v1/cav/client/visits`.

T1105
Ingress Tool Transfer

WIREFIRE has the ability to download files to compromised devices.

T1132.001
Standard Encoding

WIREFIRE can Base64 encode process output sent to C2.

T1140
Deobfuscate/Decode Files or Information

WIREFIRE can decode, decrypt, and decompress data received in C2 HTTP `POST` requests.

T1505.003
Web Shell

WIREFIRE is a web shell that can download files to and execute arbitrary commands from compromised Ivanti Connect Secure VPNs.

T1554
Compromise Host Software Binary

WIREFIRE can modify the `visits.py` component of Ivanti Connect Secure VPNs for file download and arbitrary command execution.

T1573.001
Symmetric Cryptography

WIREFIRE can AES encrypt process output sent from compromised devices to C2.

Groups that use it0

None recorded.

Campaigns1

References1

  1. Mandiant Cutting Edge January 2024 Open source
    McLellan, T. et al. (2024, January 12). Cutting Edge: Suspected APT Targets Ivanti Connect Secure VPN in New Zero-Day Exploitation. Retrieved February 27, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.