China’s UNC5337 Exploits a Critical RCE Vulnerability in Ivanti, Once More

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Chinese Threat Actor Targets Ivanti Remote Access Devices: A Year of Vulnerabilities and Exploits

Ivanti Under Siege: Chinese Threat Actor Exploits Vulnerabilities Once Again

In a troubling resurgence, a Chinese threat actor, identified as UNC5337, is once again targeting Ivanti remote access devices, exploiting newly discovered critical vulnerabilities. This follows a year marked by a barrage of significant security issues affecting Ivanti’s products, including authentication bypasses and SQL injection flaws.

This latest series of breaches hinges on vulnerabilities in Ivanti’s Connect Secure (ICS) and Policy Secure gateways, with the most severe, rated critical on the Common Vulnerability Scoring System (CVSS), allowing unauthorized code execution. Although Ivanti had pledged to prioritize secure engineering following last year’s issues, the group has already begun exploiting these new flaws, raising alarms in cybersecurity circles.

“UNC5337’s techniques highlight how sophisticated these attacks are,” notes Arctic Wolf CISO Adam Marrè. The group’s notable use of the "Spawn" malware family, which has been observed in previous exploits, underscores their expertise in infiltrating Ivanti’s systems. Tools like SpawnAnt and SpawnSnail enable extensive control and surveillance once a system is compromised.

Researchers at Mandiant warn that over 2,000 instances of ICS devices could be vulnerable globally, particularly in the US, France, and Spain. Ivanti, responding to this maturity of threat, is urging clients to implement immediate patches and utilize their built-in Integrity Checker Tool to scan for infections.

While cybersecurity leaders emphasize the need for timely updates to mitigate such risks, the task is not without its challenges. Administrators face tough decisions regarding potential downtime versus the urgency of patching systems—a dilemma that could further strain an already beleaguered IT environment.

As the threat escalates, vigilance and prompt action become paramount for organizations reliant on Ivanti solutions.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

European Parliament Calls for Delay in Serbia’s EU Accession Over Spyware Concerns

A group of European Parliament representatives is advocating for a delay in Serbia's entry into the European Union due to concerns over the government's...

Estate Planning in the UAE Embraces Digital Transformation, Says Blanket Founder

UAE Estate Planning Enters Digital Transformation Era The UAE is witnessing a significant shift in estate planning as the traditionally complex process begins to embrace...

Edge AI Shifts Security Responsibilities to Customers in New Trust Model

Edge AI shifts the responsibility of security from centralized cloud providers to customers, fundamentally altering the trust model for AI systems. Edge AI refers to...

UK Account-Hack Losses Increase 417% Amid New Reporting System Implementation

Reported losses associated with hacked email, social media, and other online accounts in the UK surged by 417% over the last financial year, reaching...