ATT&CKReferencesMandiant Cutting Edge January 2024

Mandiant Cutting Edge January 2024

McLellan, T. et al. (2024, January 12). Cutting Edge: Suspected APT Targets Ivanti Connect Secure VPN in New Zero-Day Exploitation. Retrieved February 27, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software4

Campaigns1

Procedure examples26

TechniqueUsed byProcedure example
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareWARPWIRE

WARPWIRE can send captured credentials to C2 via HTTP `GET` or `POST` requests.

T1056.003
Web Portal Capture
MalwareWARPWIRE

WARPWIRE can capture credentials submitted during the web logon process in order to access layer seven applications such as RDP.

T1057
Process Discovery
MalwareZIPLINE

ZIPLINE can identify running processes and their names.

T1059
Command and Scripting Interpreter
CampaignCutting Edge

During Cutting Edge, threat actors used Perl scripts to enable the deployment of the THINSPOOL shell script dropper and for enumerating host data.

T1059.004
Unix Shell
MalwareZIPLINE

ZIPLINE can use `/bin/sh` to create a reverse shell and execute commands.

T1059.007
JavaScript
MalwareWARPWIRE

WARPWIRE is a credential harvester written in JavaScript.

T1071.001
Web Protocols
MalwareWIREFIRE

WIREFIRE can respond to specific HTTP `POST` requests to `/api/v1/cav/client/visits`.

T1083
File and Directory Discovery
MalwareZIPLINE

ZIPLINE can find and append specific files on Ivanti Connect Secure VPNs based upon received commands.

T1090
Proxy
MalwareZIPLINE

ZIPLINE can create a proxy server on compromised hosts.

T1105
Ingress Tool Transfer
MalwareZIPLINE

ZIPLINE can download files to be saved on the compromised system.

T1105
Ingress Tool Transfer
MalwareWIREFIRE

WIREFIRE has the ability to download files to compromised devices.

T1132.001
Standard Encoding
MalwareWARPWIRE

WARPWIRE can Base64 encode captured credentials with `btoa()` prior to sending to C2.

T1132.001
Standard Encoding
MalwareWIREFIRE

WIREFIRE can Base64 encode process output sent to C2.

T1140
Deobfuscate/Decode Files or Information
MalwareWIREFIRE

WIREFIRE can decode, decrypt, and decompress data received in C2 HTTP `POST` requests.

T1190
Exploit Public-Facing Application
CampaignCutting Edge

During Cutting Edge, threat actors exploited CVE-2023-46805 and CVE-2024-21887 in Ivanti Connect Secure VPN appliances to enable authentication bypass and command injection. A server-side request forgery (SSRF) vulnerability, CVE-2024-21893, was identified later and used to bypass mitigations for the initial two vulnerabilities by chaining with CVE-2024-21887.

T1205
Traffic Signaling
MalwareZIPLINE

ZIPLINE can identify a specific string in intercepted network traffic, `SSH-2.0-OpenSSH_0.3xx.`, to trigger its command functionality.

T1505.003
Web Shell
MalwareWIREFIRE

WIREFIRE is a web shell that can download files to and execute arbitrary commands from compromised Ivanti Connect Secure VPNs.

T1505.003
Web Shell
CampaignCutting Edge

During Cutting Edge, threat actors used multiple web shells to maintain presence on compromised Connect Secure appliances such as WIREFIRE, GLASSTOKEN, BUSHWALK, LIGHTWIRE, and FRAMESTING.

T1554
Compromise Host Software Binary
MalwareLIGHTWIRE

LIGHTWIRE can imbed itself into the legitimate `compcheckresult.cgi` component of Ivanti Connect Secure VPNs to enable command execution.

T1554
Compromise Host Software Binary
MalwareWARPWIRE

WARPWIRE can embed itself into a legitimate file on compromised Ivanti Connect Secure VPNs.

T1554
Compromise Host Software Binary
CampaignCutting Edge

During Cutting Edge, threat actors trojanized legitimate files in Ivanti Connect Secure appliances with malicious code.

T1554
Compromise Host Software Binary
MalwareWIREFIRE

WIREFIRE can modify the `visits.py` component of Ivanti Connect Secure VPNs for file download and arbitrary command execution.

T1573.001
Symmetric Cryptography
MalwareWIREFIRE

WIREFIRE can AES encrypt process output sent from compromised devices to C2.

T1584.008
Network Devices
CampaignCutting Edge

During Cutting Edge, threat actors used compromised and out-of-support Cyberoam VPN appliances for C2.

T1588.002
Tool
CampaignCutting Edge

During Cutting Edge, threat actors leveraged tools including Interactsh to identify vulnerable targets, PySoxy to simultaneously dispatch traffic between multiple endpoints, BusyBox to enable post exploitation activities, and Kubo Injector to inject shared objects into process memory.

T1685
Disable or Modify Tools
MalwareZIPLINE

ZIPLINE can add itself to the exclusion list for the Ivanti Connect Secure Integrity Checker Tool if the `--exclude` parameter is passed by the `tar` process.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.