BUSHWALK

S1118

Malware.View on attack.mitre.org

About this malware

BUSHWALK is a web shell written in Perl that was inserted into the legitimate querymanifest.cgi file on compromised Ivanti Connect Secure VPNs during Cutting Edge.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1027
Obfuscated Files or Information

BUSHWALK can encrypt the resulting data generated from C2 commands with RC4.

T1105
Ingress Tool Transfer

BUSHWALK can write malicious payloads sent through a web request’s command parameter.

T1140
Deobfuscate/Decode Files or Information

BUSHWALK can Base64 decode and RC4 decrypt malicious payloads sent through a web request’s command parameter.

T1205
Traffic Signaling

BUSHWALK can modify the `DSUserAgentCap.pm` Perl module on Ivanti Connect Secure VPNs and either activate or deactivate depending on the value of the user agent in incoming HTTP requests.

T1505.003
Web Shell

BUSHWALK is a web shell that has the ability to execute arbitrary commands or write files.

T1554
Compromise Host Software Binary

BUSHWALK can embed into the legitimate `querymanifest.cgi` file on compromised Ivanti Connect Secure VPNs.

Groups that use it0

None recorded.

Campaigns1

References2

  1. Mandiant Cutting Edge Part 2 January 2024 Open source
    Lin, M. et al. (2024, January 31). Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation. Retrieved February 27, 2024.
  2. Mandiant Cutting Edge Part 3 February 2024 Open source
    Lin, M. et al. (2024, February 27). Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts. Retrieved March 1, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.