LIGHTWIRE

S1119

Malware.View on attack.mitre.org

About this malware

LIGHTWIRE is a web shell written in Perl that was used during Cutting Edge to maintain access and enable command execution by imbedding into the legitimate compcheckresult.cgi component of Ivanti Secure Connect VPNs.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1071.001
Web Protocols

LIGHTWIRE can use HTTP for C2 communications.

T1140
Deobfuscate/Decode Files or Information

LIGHTWIRE can RC4 decrypt and Base64 decode C2 commands.

T1505.003
Web Shell

LIGHTWIRE is a web shell capable of command execution and establishing persistence on compromised Ivanti Secure Connect VPNs.

T1554
Compromise Host Software Binary

LIGHTWIRE can imbed itself into the legitimate `compcheckresult.cgi` component of Ivanti Connect Secure VPNs to enable command execution.

T1573.001
Symmetric Cryptography

LIGHTWIRE can RC4 encrypt C2 commands.

Groups that use it0

None recorded.

Campaigns1

References2

  1. Mandiant Cutting Edge January 2024 Open source
    McLellan, T. et al. (2024, January 12). Cutting Edge: Suspected APT Targets Ivanti Connect Secure VPN in New Zero-Day Exploitation. Retrieved February 27, 2024.
  2. Mandiant Cutting Edge Part 2 January 2024 Open source
    Lin, M. et al. (2024, January 31). Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation. Retrieved February 27, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.