{"id":11469,"date":"2025-07-20T12:35:42","date_gmt":"2025-07-20T05:35:42","guid":{"rendered":"https:\/\/infosec.new88088.net\/?p=11469"},"modified":"2026-06-25T10:00:16","modified_gmt":"2026-06-25T03:00:16","slug":"hackers-exploiting-ivanti-vulnerabilities-to-spread-malicious-code-and-deploy-cobalt-strike","status":"publish","type":"post","link":"https:\/\/infosec.new88088.net\/en\/2025\/07\/20\/hackers-exploiting-ivanti-vulnerabilities-to-spread-malicious-code-and-deploy-cobalt-strike\/","title":{"rendered":"Hackers exploiting Ivanti vulnerabilities to spread malicious code and deploy Cobalt Strike"},"content":{"rendered":"<div style=\"text-align: justify\"><b>Recently, cybersecurity experts discovered a new type of malware called MDifyLoader, which is used in cyberattacks targeting Ivanti Connect Secure (ICS) devices.<\/b><br \/>\n\u200b<\/div>\n<div style=\"text-align: center\"><a class=\"js-lbImage\" style=\"cursor: pointer\" href=\"https:\/\/whitehat.vn\/attachments\/1752982631336-png.17339\/\" target=\"_blank\" rel=\"noopener\" data-caption=\"&lt;h4&gt;1752982631336.png&lt;\/h4&gt;&lt;p&gt;&lt;a href=&quot;https:&amp;#x2F;&amp;#x2F;whitehat.vn&amp;#x2F;threads&amp;#x2F;tin-tac-khai-thac-lo-hong-ivanti-de-phat-tan-ma-doc-va-trien-khai-cobalt-strike.18580&amp;#x2F;#post-44087&quot; class=&quot;js-lightboxCloser&quot;&gt;WhiteHat Team \u00b7 20&amp;#x2F;07&amp;#x2F;2025 l\u00fac 10:58 AM&lt;\/a&gt;&lt;\/p&gt;\" data-fancybox=\"lb-thread-18580\" data-lb-caption-extra-html=\"\" data-lb-sidebar-href=\"\"><img fetchpriority=\"high\" decoding=\"async\" class=\"bbImage\" title=\"1752982631336.png\" src=\"https:\/\/whitehat.vn\/data\/attachments\/17\/17674-109ec8304001601e106208aaa4450e69.jpg\" alt=\"1752982631336.png\" width=\"714\" height=\"400\" \/><\/a>\u200b<\/div>\n<div style=\"text-align: justify\">\n<p>Discovered between December 2024 and July 2035, this attack exploits two security vulnerabilities in the ICS to infect and spread dangerous malicious codes such as Cobalt Strike, VShell and Fscan:<\/p>\n<p>MDifyLoader is a loader designed to load other malware into the system&#8217;s memory. The software is based on the open source libPeConv project and performs the download and decryption of an encrypted Cobalt Strike Beacon payload.<\/p>\n<p>Download and decode MDifyLoader: Once access is granted, the MDificateLOader is loaded into memory, loading an encrypted Cobalt Strike Beacon payload.<\/p>\n<p>Lateral movement: After gaining access to the system, hackers perform brute-force attacks on FTP, MS-SQL and SSH to steal passwords and data.<\/p>\n<p>Cobalt Strike is a powerful tool, commonly used in cyberattacks to remotely control systems and deploy complex attack operations. The Cobalt Strike Beacon can allow hackers to maintain access to an infiltrated system and perform stealth activities that the user is unaware of.<\/p>\n<p>Taking advantage of other tools: Tools such as VShell and Fscan are used to maintain control and scan additional network devices to expand the range of attacks.<\/p>\n<p>VShell: A remote control tool (RAT) written in Go, used to maintain access to the system. VShell checks the system language to determine if it is a Chinese user, before taking action.<\/p>\n<p>Fscan: A network scanning tool written in Go, which helps hackers scan devices and systems in a network to search for vulnerabilities and expand the range of attacks.<\/p>\n<p>The attack process can be described as follows: The vulnerability in Ivanti Connect Secure (ICS), a VPN device widely used in businesses, is the starting point for this attack sequence. The following two serious security vulnerabilities have been exploited by hackers:<\/p>\n<\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">CVE-2025-0282: This is a vulnerability that allows remote code execution without authentication. The breach was discovered and patched by Ivanti in January 2025.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">CVE-2025-22457: This vulnerability is related to stack buffer overflow, allowing arbitrary code execution, and was patched in April 2015.<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: justify\">\n<p>Hackers exploited the CVE-2025-0282 and CVZ-22457 security vulnerabilities in Ivanti Connect Secure devices to infiltrate organizations&#8217; internal networks. Both of these vulnerabilities have been exploited by hackers as zero-day vulnerabilities. This means that organizations have not patched up the holes when they are exploited in actual attacks.<\/p>\n<p>This attack posed many major threats to the organizations:<\/p>\n<\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Data loss risk: Hackers can steal sensitive data like login information, financial data, or even customer data.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">System appropriation: Organizations can lose control of the system and face the risk of further attacks.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Business Execution: Being attacked can disrupt business operations, causing time and cost to recover.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Leaving the door open for the following attacks: Hackers can install backdoors or hidden accounts in the system, helping them maintain long-term access even when other security measures are taken.<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: justify\">To protect systems from such attacks, organizations and users need to take some of the following measures:<\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Software updates and security patches: Ensuring that all security patches, especially for Ivanti Connect Secure, are applied in a timely manner.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Network system checks and protection: It is necessary to scan and secure the system to detect signs of malware, such as Cobalt Strike or VShell.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Use strong authentication methods: Apply Multi-factor authentication (MFA) to minimize the risk of an account being attacked.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Systems behavioral monitoring: Deploying network and system monitoring tools to detect abnormal activity or signs of intrusion.<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: justify\">Attacks via MDifyLoader have shown the sophistication and complexity of current cyber threats. Exploitation of the flaws in Ivanti Connect Secure allowed hackers to hijack the system and commit stealth attacks. Organizations need to pay attention to strong security measures and quickly adopt security patches to prevent further attacks.<\/div>\n<div style=\"text-align: right\"><b><i>Synthetic WhiteHat<\/i><\/b>\u200b<\/div>\n<div style=\"text-align: right;margin-top: 16px\"><i>Theo: <a href=\"https:\/\/whitehat.vn\/threads\/tin-tac-khai-thac-lo-hong-ivanti-de-phat-tan-ma-doc-va-trien-khai-cobalt-strike.18580\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/whitehat.vn\/threads\/tin-tac-khai-thac-lo-hong-ivanti-de-phat-tan-ma-doc-va-trien-khai-cobalt-strike.18580\/<\/a><\/i><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Recently, cybersecurity experts discovered a new type of malware called MDifyLoader, which is used in cyberattacks targeting Ivanti Connect Secure (ICS) devices. \u200b \u200b Discovered between December 2024 and July 2035, this attack exploits two security vulnerabilities in the ICS to infect and spread dangerous malicious codes such as Cobalt Strike, VShell and Fscan: MDifyLoader [&hellip;]<\/p>\n","protected":false},"author":46,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[351],"tags":[],"class_list":["post-11469","post","type-post","status-publish","format-standard","hentry","category-news-announcements"],"_links":{"self":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11469","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/comments?post=11469"}],"version-history":[{"count":2,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11469\/revisions"}],"predecessor-version":[{"id":11652,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11469\/revisions\/11652"}],"wp:attachment":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/media?parent=11469"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/categories?post=11469"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/tags?post=11469"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}