The China-linked threat group responsible for a concerted attack on Ivanti network devices has developed “significant knowledge” of the appliances, researchers believe.So far this year, Ivanti has issued patches for five high- and critical-severity vulnerabilities affecting its Connect Secure, Policy Secure, and Neurons for Zero Trust Access appliances.While researchers have previously said they suspected a Chinese nation-state threat actors were responsible for exploiting the vulnerabilities, attribution to a specific group has remained elusive.In a Feb. 27 post, researchers at Mandiant — who were hired by Ivanti to help mitigate the impact of the attacks — have linked the actors to another threat group believed to have used similar techniques in the past to target virtualization technologies. Mandiant is tracking the actors responsible for the Ivanti attacks as UNC5325 and said in its post the group was using a combination of living-off-the-land techniques to evade detection and novel malware to persist across system upgrades, patches and factory resets. (Mandiant uses a UNC prefix to label “uncategorized” threat groups that have not been fully defined.)“While the limited attempts observed to maintain persistence have not been successful to date due to a lack of logic in the malware's code to account for an encryption key mismatch, it further demonstrates the lengths UNC5325 will go to maintain access to priority targets and highlights the importance of ensuring network appliances have the latest updates and patches,” the researchers said.
Network Security, Threat Intelligence, Endpoint/Device Security
Ivanti attacks linked to espionage group targeting defense contractors

A China-linked group is suspected of targeting vulnerabilities in Ivanti devices. (Adobe Stock)
An In-Depth Guide to Network Security
Get essential knowledge and practical strategies to fortify your network security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds