# Ivanti Connect Secure exploits deploy Cobalt Strike, vshell

Published: 2025-07-18 · Severity: high · Sectors: technology, telecommunications
Canonical: https://vorant.io/reports/5e4a9308-010a-4c76-9a75-2bd2af29655d/ivanti-connect-secure-exploits-deploy-cobalt-strike-vshell

> JPCERT/CC observes attackers exploiting Ivanti Connect Secure CVE-2025-0282 and CVE-2025-22457 to deploy custom loaders, Cobalt Strike, vshell RAT, and Fscan network scanner since December 2024.

JPCERT/CC has identified ongoing exploitation of Ivanti Connect Secure vulnerabilities CVE-2025-0282 and CVE-2025-22457 from December 2024 through July 2025. Attackers deploy MDifyLoader, a custom loader based on libPeConv that uses RC4 decryption with keys derived from MD5 hashes of executable files, to launch Cobalt Strike Beacon version 4.5 through DLL side-loading. The loader contains extensive junk code to hinder analysis, and the Beacon itself uses custom RC4 encryption with the hardcoded key "google" for configuration data. Additional tools include vshell version 4.6.0, a Go-based multi-platform RAT with Chinese language checks, and Fscan, an open-source network scanner loaded via a FilelessRemotePE-based loader with ETW bypass capabilities.

Post-compromise activities demonstrate sophisticated tradecraft including brute-force attacks against Active Directory servers, exploitation of MS17-010 against unpatched systems, and lateral movement via RDP and SMB using stolen credentials. For persistence, attackers create domain accounts added to existing groups, register malware as services or scheduled tasks, and maintain long-term access through blended accounts. Defense evasion techniques include multi-stage loading through legitimate executables like rmic.exe, push_detect.exe, and python.exe, ETW bypass in ntdll.dll, and fileless execution to evade EDR detection.

The campaign targets VPN devices and demonstrates active, persistent exploitation with repeated deployment attempts and tool refinement. Organizations using Ivanti Connect Secure should prioritize patching these vulnerabilities and monitor for indicators associated with this ongoing threat activity.

## Mentioned in this report

- Vulnerabilities: CVE-2017-0144 (KEV), CVE-2025-0282 (KEV), CVE-2025-22457 (KEV)
- Malware: Cobalt Strike, DslogdRAT, Fscan, MDifyLoader, SPAWNCHIMERA, VShell

3 more detection artefacts for this report (IOC-atomic rules, Splunk/KQL/Elastic conversions, YARA, Suricata) are available to subscribers.

Source reporting: https://blogs.jpcert.or.jp/en/2025/07/ivanti_cs.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5e4a9308-010a-4c76-9a75-2bd2af29655d/ivanti-connect-secure-exploits-deploy-cobalt-strike-vshell.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
