Lin, M. et al. (2024, January 31). Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation. Retrieved February 27, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001 Data Obfuscation |
MalwareFRAMESTING | FRAMESTING can send and receive zlib compressed data within `POST` requests. |
| T1001.003 Protocol or Service Impersonation |
MalwareFRAMESTING | FRAMESTING uses a cookie named `DSID` to mimic the name of a cookie used by Ivanti Connect Secure appliances for maintaining VPN sessions. |
| T1005 Data from Local System |
CampaignCutting Edge | During Cutting Edge, threat actors stole the running configuration and cache data from targeted Ivanti Connect Secure VPNs. |
| T1027 Obfuscated Files or Information |
MalwareBUSHWALK | BUSHWALK can encrypt the resulting data generated from C2 commands with RC4. |
| T1027.013 Encrypted/Encoded File |
CampaignCutting Edge | During Cutting Edge, threat actors used a Base64-encoded Python script to write a patched version of the Ivanti Connect Secure `dsls` binary. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwareWARPWIRE | WARPWIRE can send captured credentials to C2 via HTTP `GET` or `POST` requests. |
| T1059 Command and Scripting Interpreter |
CampaignCutting Edge | During Cutting Edge, threat actors used Perl scripts to enable the deployment of the THINSPOOL shell script dropper and for enumerating host data. |
| T1059.006 Python |
MalwareFRAMESTING | FRAMESTING is a Python web shell that can embed in the Ivanti Connect Secure CAV Python package. |
| T1070 Indicator Removal |
CampaignCutting Edge | During Cutting Edge, threat actors cleared logs to remove traces of their activity and restored compromised systems to a clean state to bypass manufacturer mitigations for CVE-2023-46805 and CVE-2024-21887. |
| T1070.004 File Deletion |
CampaignCutting Edge | During Cutting Edge, threat actors deleted `/tmp/test1.txt` on compromised Ivanti Connect Secure VPNs which was used to hold stolen configuration and cache files. |
| T1070.006 Timestomp |
CampaignCutting Edge | During Cutting Edge, threat actors changed timestamps of multiple files on compromised Ivanti Secure Connect VPNs to conceal malicious activity. |
| T1071.001 Web Protocols |
MalwareFRAMESTING | FRAMESTING can retrieve C2 commands from values stored in the `DSID` cookie from the current HTTP request or from decompressed zlib data within the request's `POST` data. |
| T1071.001 Web Protocols |
MalwareLIGHTWIRE | LIGHTWIRE can use HTTP for C2 communications. |
| T1071.004 DNS |
CampaignCutting Edge | During Cutting Edge, threat actors used DNS to tunnel IPv4 C2 traffic. |
| T1082 System Information Discovery |
CampaignCutting Edge | During Cutting Edge, threat actors used the ENUM4LINUX Perl script for discovery on Windows and Samba hosts. |
| T1090 Proxy |
MalwareZIPLINE | ZIPLINE can create a proxy server on compromised hosts. |
| T1095 Non-Application Layer Protocol |
MalwareZIPLINE | ZIPLINE can communicate with C2 using a custom binary protocol. |
| T1105 Ingress Tool Transfer |
MalwareZIPLINE | ZIPLINE can download files to be saved on the compromised system. |
| T1105 Ingress Tool Transfer |
MalwareBUSHWALK | BUSHWALK can write malicious payloads sent through a web request’s command parameter. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareFRAMESTING | FRAMESTING can decompress data received within `POST` requests. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBUSHWALK | BUSHWALK can Base64 decode and RC4 decrypt malicious payloads sent through a web request’s command parameter. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLIGHTWIRE | LIGHTWIRE can RC4 decrypt and Base64 decode C2 commands. |
| T1190 Exploit Public-Facing Application |
CampaignCutting Edge | During Cutting Edge, threat actors exploited CVE-2023-46805 and CVE-2024-21887 in Ivanti Connect Secure VPN appliances to enable authentication bypass and command injection. A server-side request forgery (SSRF) vulnerability, CVE-2024-21893, was identified later and used to bypass mitigations for the initial two vulnerabilities by chaining with CVE-2024-21887. |
| T1505.003 Web Shell |
MalwareLIGHTWIRE | LIGHTWIRE is a web shell capable of command execution and establishing persistence on compromised Ivanti Secure Connect VPNs. |
| T1505.003 Web Shell |
MalwareBUSHWALK | BUSHWALK is a web shell that has the ability to execute arbitrary commands or write files. |
| T1505.003 Web Shell |
MalwareFRAMESTING | FRAMESTING is a web shell capable of enabling arbitrary command execution on compromised Ivanti Connect Secure VPNs. |
| T1554 Compromise Host Software Binary |
MalwareLIGHTWIRE | LIGHTWIRE can imbed itself into the legitimate `compcheckresult.cgi` component of Ivanti Connect Secure VPNs to enable command execution. |
| T1554 Compromise Host Software Binary |
MalwareFRAMESTING | FRAMESTING can embed itself in the CAV Python package of an Ivanti Connect Secure VPN located in `/home/venv3/lib/python3.6/site-packages/cav-0.1-py3.6.egg/cav/api/resources/category.py.` |
| T1554 Compromise Host Software Binary |
CampaignCutting Edge | During Cutting Edge, threat actors trojanized legitimate files in Ivanti Connect Secure appliances with malicious code. |
| T1554 Compromise Host Software Binary |
MalwareBUSHWALK | BUSHWALK can embed into the legitimate `querymanifest.cgi` file on compromised Ivanti Connect Secure VPNs. |
| T1560.001 Archive via Utility |
CampaignCutting Edge | During Cutting Edge, threat actors saved collected data to a tar archive. |
| T1572 Protocol Tunneling |
CampaignCutting Edge | During Cutting Edge, threat actors used Iodine to tunnel IPv4 traffic over DNS. |
| T1573.001 Symmetric Cryptography |
MalwareZIPLINE | ZIPLINE can use AES-128-CBC to encrypt data for both upload and download. |
| T1573.001 Symmetric Cryptography |
MalwareLIGHTWIRE | LIGHTWIRE can RC4 encrypt C2 commands. |
| T1685 Disable or Modify Tools |
CampaignCutting Edge | During Cutting Edge, threat actors disabled logging and modified the `compcheckresult.cgi` component to edit the Ivanti Connect Secure built-in Integrity Checker exclusion list to evade detection. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.