Meltzer, M. et al. (2024, January 10). Active Exploitation of Two Zero-Day Vulnerabilities in Ivanti Connect Secure VPN. Retrieved February 27, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
CampaignCutting Edge | During Cutting Edge, threat actors used Task Manager to dump LSASS memory from Windows devices to disk. |
| T1003.003 NTDS |
CampaignCutting Edge | During Cutting Edge, threat actors accessed and mounted virtual hard disk backups to extract |
| T1005 Data from Local System |
CampaignCutting Edge | During Cutting Edge, threat actors stole the running configuration and cache data from targeted Ivanti Connect Secure VPNs. |
| T1021.001 Remote Desktop Protocol |
CampaignCutting Edge | During Cutting Edge, threat actors used RDP with compromised credentials for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
CampaignCutting Edge | During Cutting Edge, threat actors moved laterally using compromised credentials to connect to internal Windows systems with SMB. |
| T1021.004 SSH |
CampaignCutting Edge | During Cutting Edge, threat actors used SSH for lateral movement. |
| T1056.001 Keylogging |
CampaignCutting Edge | During Cutting Edge, threat actors modified a JavaScript file on the Web SSL VPN component of Ivanti Connect Secure devices to keylog credentials. |
| T1056.003 Web Portal Capture |
CampaignCutting Edge | During Cutting Edge, threat actors modified the JavaScript loaded by the Ivanti Connect Secure login page to capture credentials entered. |
| T1059.001 PowerShell |
MalwareGLASSTOKEN | GLASSTOKEN can use PowerShell for command execution. |
| T1059.006 Python |
CampaignCutting Edge | During Cutting Edge, threat actors used a Python reverse shell and the PySoxy SOCKS5 proxy tool. |
| T1070 Indicator Removal |
CampaignCutting Edge | During Cutting Edge, threat actors cleared logs to remove traces of their activity and restored compromised systems to a clean state to bypass manufacturer mitigations for CVE-2023-46805 and CVE-2024-21887. |
| T1071.001 Web Protocols |
MalwareWIREFIRE | WIREFIRE can respond to specific HTTP `POST` requests to `/api/v1/cav/client/visits`. |
| T1078.002 Domain Accounts |
CampaignCutting Edge | During Cutting Edge, threat actors used compromised VPN accounts for lateral movement on targeted networks. |
| T1105 Ingress Tool Transfer |
CampaignCutting Edge | During Cutting Edge, threat actors leveraged exploits to download remote files to Ivanti Connect Secure VPNs. |
| T1132.001 Standard Encoding |
MalwareGLASSTOKEN | GLASSTOKEN has hexadecimal and Base64 encoded C2 content. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareGLASSTOKEN | GLASSTOKEN has the ability to decode hexadecimal and Base64 C2 requests. |
| T1190 Exploit Public-Facing Application |
CampaignCutting Edge | During Cutting Edge, threat actors exploited CVE-2023-46805 and CVE-2024-21887 in Ivanti Connect Secure VPN appliances to enable authentication bypass and command injection. A server-side request forgery (SSRF) vulnerability, CVE-2024-21893, was identified later and used to bypass mitigations for the initial two vulnerabilities by chaining with CVE-2024-21887. |
| T1505.003 Web Shell |
MalwareGLASSTOKEN | GLASSTOKEN is a web shell capable of tunneling C2 connections and code execution on compromised Ivanti Secure Connect VPNs. |
| T1505.003 Web Shell |
CampaignCutting Edge | During Cutting Edge, threat actors used multiple web shells to maintain presence on compromised Connect Secure appliances such as WIREFIRE, GLASSTOKEN, BUSHWALK, LIGHTWIRE, and FRAMESTING. |
| T1554 Compromise Host Software Binary |
CampaignCutting Edge | During Cutting Edge, threat actors trojanized legitimate files in Ivanti Connect Secure appliances with malicious code. |
| T1554 Compromise Host Software Binary |
MalwareWIREFIRE | WIREFIRE can modify the `visits.py` component of Ivanti Connect Secure VPNs for file download and arbitrary command execution. |
| T1594 Search Victim-Owned Websites |
CampaignCutting Edge | During Cutting Edge, threat actors peformed reconnaissance of victims' internal websites via proxied connections. |
| T1685 Disable or Modify Tools |
CampaignCutting Edge | During Cutting Edge, threat actors disabled logging and modified the `compcheckresult.cgi` component to edit the Ivanti Connect Secure built-in Integrity Checker exclusion list to evade detection. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.