VORANT. Threat Intelligence Sign in Get the full feed

Ivanti Connect Secure exploits deploy Cobalt Strike, vshell

high threat technologytelecommunications

JPCERT/CC observes attackers exploiting Ivanti Connect Secure CVE-2025-0282 and CVE-2025-22457 to deploy custom loaders, Cobalt Strike, vshell RAT, and Fscan network scanner since December 2024.

JPCERT/CC has identified ongoing exploitation of Ivanti Connect Secure vulnerabilities CVE-2025-0282 and CVE-2025-22457 from December 2024 through July 2025. Attackers deploy MDifyLoader, a custom loader based on libPeConv that uses RC4 decryption with keys derived from MD5 hashes of executable files, to launch Cobalt Strike Beacon version 4.5 through DLL side-loading. The loader contains extensive junk code to hinder analysis, and the Beacon itself uses custom RC4 encryption with the hardcoded key "google" for configuration data. Additional tools include vshell version 4.6.0, a Go-based multi-platform RAT with Chinese language checks, and Fscan, an open-source network scanner loaded via a FilelessRemotePE-based loader with ETW bypass capabilities.

Post-compromise activities demonstrate sophisticated tradecraft including brute-force attacks against Active Directory servers, exploitation of MS17-010 against unpatched systems, and lateral movement via RDP and SMB using stolen credentials. For persistence, attackers create domain accounts added to existing groups, register malware as services or scheduled tasks, and maintain long-term access through blended accounts. Defense evasion techniques include multi-stage loading through legitimate executables like rmic.exe, push_detect.exe, and python.exe, ETW bypass in ntdll.dll, and fileless execution to evade EDR detection.

The campaign targets VPN devices and demonstrates active, persistent exploitation with repeated deployment attempts and tool refinement. Organizations using Ivanti Connect Secure should prioritize patching these vulnerabilities and monitor for indicators associated with this ongoing threat activity.

Mentioned in this report

Vulnerabilities CVE-2017-0144KEVCVE-2025-0282KEVCVE-2025-22457KEV
Malware Cobalt StrikeDslogdRATFscanMDifyLoaderSPAWNCHIMERAVShell

Detection guidance

3 detection artefacts for this report are available to subscribers.

Source reporting: https://blogs.jpcert.or.jp/en/2025/07/ivanti_cs.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free