PHASEJAM

S9014

Malware.View on attack.mitre.org

About this malware

PHASEJAM is a dropper written as a bash shell script that modifies Ivanti Connect Secure appliance components. PHASEJAM was first reported in January 2025. PHASEJAM has previously been leveraged by People's Republic of China (PRC)- affiliated actors identified as UNC5221 and SYLVANITE.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1027.010
Command Obfuscation

PHASEJAM has encoded commands with Base64.

T1027.013
Encrypted/Encoded File

PHASEJAM has launched a webshell using the `MIME::Base64` module that encoded and decoded Base64 commands.

T1036.003
Rename Legitimate Utilities

PHASEJAM has renamed the file `/home/bin/remotedebug` to `remotedebug.bak`, allowing the threats actors to write a malicious `/home/bin/remotedebug` shell script.

T1041
Exfiltration Over C2 Channel

PHASEJAM has the ability to exfiltrate data from the victim appliance.

T1059.008
Network Device CLI

PHASEJAM has leveraged native commands associated with the compromised network appliance to execute code.

T1105
Ingress Tool Transfer

PHASEJAM has the ability to upload files onto the compromised appliance.

T1140
Deobfuscate/Decode Files or Information

PHASEJAM has the ability to decode Base64 commands and data.

T1489
Service Stop

PHASEJAM has disabled the `cgi-server` process on Ivanti Connect Secure appliances.

T1505.003
Web Shell

PHASEJAM has inserted Perl-based web shells into legitimate files that provided threat actors with remote access and code execution capabilities on the compromised network appliance.

T1546.004
Unix Shell Configuration Modification

PHASEJAM has used a bash script to modify components on Ivanti Connect Secure appliances and execute files via `/bin/bash`.[1] It has also used the Linux stream editor (`sed`) to execute commands.

T1554
Compromise Host Software Binary

PHASEJAM has modified legitimate components to enable persistence and execution, including inserting a web shell into `getComponent.cgi` and `restAuth.cgi`, modifying `DSUpgrade.pm` to block system upgrades, and overwriting `remotedebug` to execute arbitrary commands when specific parameters are provided.

T1565
Data Manipulation

PHASEJAM has blocked legitimate upgrades of Ivanti Connect Secure systems and falsely indicates a successful upgrade while operating on an older version.

T1678
Delay Execution

PHASEJAM has used the `sleep` command within its code to generate a fake HTML upgrade progress bar that mimics a running process.

T1685
Disable or Modify Tools

PHASEJAM has modified Ivanti Connect Secure appliances and blocks the system upgrades by altering the DSUpgrade.pm file.

T1685.003
Modify or Spoof Tool UI

PHASEJAM has prevented legitimate Ivanti Connect Secure system upgrades by intercepting the upgrade command and rendering fake HTML upgrade progress bar through a function called `processUpgradeDisplay()` which allowed the compromised device to remain under the control of the adversary.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. Dragos SYLVANITE MuddyWater Electrum March 2026 Open source
    Dragos. (2026, March 24). Dragos 2026 OT Cybersecurity Report: Year in Review, O&G and Petrochemicals Focus. Retrieved April 17, 2026.
  2. Google UNC5221 Ivanti January 2025 Open source
    John Wolfram, Josh Murchie, Matt Lin, Daniel Ainsworth, Robert Wallace, Dimiter Andonov, Dhanesh Kizhakkinan, Jacob Thompson. (2025, January 8). Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation. Retrieved April 14, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.