Ivanti has disclosed actively exploiting a critical zero-day vulnerability, CVE-2025-0282, in its Connect Secure VPN appliances.
This vulnerability allows unauthenticated remote code execution and has already been exploited in a limited number of cases.
A second vulnerability, CVE-2025-0283, which enables local privilege escalation, has also been identified but is not known to have been exploited.
Ivanti revealed that CVE-2025-0282 has been exploited in a limited number of Ivanti Connect Secure appliances. The exploitation was detected using Ivanti’s Integrity Checker Tool (ICT), which flagged malicious activity on affected systems.
However, no evidence suggests exploitation of this vulnerability in Ivanti Policy Secure or ZTA gateways.
The second vulnerability, CVE-2025-0283, was discovered during internal investigations but has not been exploited in the wild as of the disclosure date.
Ivanti has released an emergency patch for Connect Secure devices, resolving both vulnerabilities in version 22.7R2.5. Patches for Policy Secure and Neurons for ZTA gateways are scheduled for release on January 21, 2025.
For affected customers:
Mandiant observed that the exploitation of CVE-2025-0282 was linked to a sophisticated threat actor cluster known as UNC5337, which is believed to be part of UNC5221.
The attackers deployed malware from the SPAWN ecosystem, including tools like SPAWNANT (installer), SPAWNMOLE (tunneler), and SPAWNSNAIL (SSH backdoor). These activities highlight the growing risks posed by advanced persistent threats targeting enterprise VPNs.
To help customers identify potential compromises, Ivanti recommends the use of its Integrity Checker Tool (ICT), both internally and externally. The ICT provides a snapshot of the current state of an appliance by analyzing file integrity and detecting unauthorized changes.
Ivanti has also released examples of how ICT scan results should appear on compromised versus uncompromised devices, emphasizing the importance of analyzing the number of steps reported by the output.
However, cybersecurity firm Mandiant has observed attempts by threat actors to evade detection by ICT. These efforts include returning compromised appliances to a clean state, recalculating hashes, and other anti-forensic techniques.
Ivanti has acknowledged that ICT has limitations, as it cannot detect past malicious activity if attackers have removed evidence or restored the system to an unaltered state. Additionally, ICT does not scan for malware or other Indicators of Compromise (IoCs).
IoCs
| Code Family | Filename | Description |
| DRYHOOK | n/a | Credential Theft Tool |
| PHASEJAM | /tmp/s | Web Shell dropper |
| PHASEJAM Webshell | /home/webserver/htdocs/dana-na/auth/getComponent.cgi | Web Shell |
| PHASEJAM Webshell | /home/webserver/htdocs/dana-na/auth/restAuth.cgi | Web Shell |
| SPAWNSNAIL | /root/home/lib/libsshd.so | SSH backdoor |
| SPAWNMOLE | /root/home/lib/libsocks5.so | Tunneler |
| SPAWNANT | /root/lib/libupgrade.so | Installer |
| SPAWNSLOTH | /tmp/.liblogblock.so | Log tampering utility |
ANY.RUN Threat Intelligence Lookup - Extract Millions of IOC's for Interactive Malware Analysis: Try for Free
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…