Malware, Vulnerability Management

Novel MDifyLoader malware spread via Ivanti zero-day

Privacy concept: pixelated words Malware on digital background, 3d render

Threat actors have been leveraging an n-day vulnerability impacting Ivanti Connect Secure appliances, tracked as CVE-2025-0282 and CVE-2025-22457, to deploy the new MDifyLoader malware as part of attacks that have been underway since December, according to The Hacker News.

Aside from having the MDifyLoader malware deliver the Cobalt Strike beacon in-memory via DLL side-loading, intrusions also involved the VShell remote access tool and the Fscan open-source network scanning utility to facilitate internal network access, a report from Japan's Computer Emergency Response Team Coordination Center showed. Microsoft SQL, FTP, and SSH servers were then targeted in brute-force attacks with the EternalBlue SMB exploit for credential theft, lateral movement, and subsequent new domain account creation. "These accounts blend in with normal operations, enabling long-term access to the internal network. Additionally, the attackers registered their malware as a service or a task scheduler to maintain persistence, ensuring it would run at system startup or upon specific event triggers," said JPCERT/CC researcher Yuma Masubuchi.

A spokesperson for Ivanti issued the following statement in a July 25 email to SC Media:

These vulnerabilities were previously identified and patched by Ivanti. Customers that are on the latest version of Ivanti Connect Secure are not vulnerable.

 CVE-2025-22457 was patched by Ivanti in February 2025. It is an N-Day that only affected unpatched or older versions of Ivanti products, including a Pulse Connect Secure version that is no longer supported.

CVE-2025-0282 was patched in January. Customers who patched and followed Ivanti’s instructions at the time have addressed this vulnerability.

The security and protection of our customers remain our top priority, and Ivanti strongly encourages customers to remain on the latest version of a solution so they can benefit from important security and product enhancements.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds