Ivanti Connect Secure zero-days: one December intrusion, 2,100 backdoored appliances and a federal disconnect order
By Sethu Satheesh · 13 Sept 2026 · 18 min read
Threat Actor: UNC5221 / UTA0178 (suspected China-nexus espionage); follow-on clusters UNC5325, UNC5330, UNC5337; opportunistic actors after disclosure · Target: Operators of Ivanti Connect Secure and Policy Secure gateways worldwide, including US federal agencies (CISA CSAT)
Source: www.volexity.com
Executive Summary
In the second week of December 2023, Volexity's network monitoring flagged lateral movement inside one customer's network and traced it to that organisation's Internet-facing Ivanti Connect Secure VPN appliance. The device had been compromised through two previously unknown vulnerabilities: CVE-2023-46805, an authentication bypass in the web component (CVSS 8.2), and CVE-2024-21887, a command injection reachable by an authenticated administrator (CVSS 9.1). Chained, they gave an unauthenticated attacker arbitrary command execution on the appliance. Ivanti published the advisory and a mitigation XML on 10 January 2024; patches for the first affected versions did not ship until 31 January.
The actor Volexity tracked as UTA0178 and Mandiant as UNC5221 had been quiet and careful: web shells written into legitimate appliance files (LIGHTWIRE in compcheckresult.cgi, WIREFIRE in visits.py), a JavaScript credential harvester (WARPWIRE) appended to the login page, command-and-control through compromised out-of-support Cyberoam VPN appliances inside the victims' own countries, and a modified built-in Integrity Checker Tool that reported "no findings" regardless of what it found. That changed the moment the vulnerabilities were public. Volexity observed widespread exploitation from 11 January; by 15 January it had found GIFTEDVISITOR web shells on more than 1,700 appliances, by 18 January on more than 2,100, in governments, militaries, telecoms, defence contractors and Fortune 500 companies. Other actors deployed XMRig miners.
The response was unusual in its severity. CISA issued Emergency Directive 24-01 on 19 January requiring federal agencies to apply the mitigation within three days. When Ivanti disclosed two more flaws on 31 January, one of which (CVE-2024-21893, SSRF in the SAML component) let attackers bypass the 10 January mitigation, CISA ordered every federal Connect Secure and Policy Secure appliance disconnected from the network by 2 February, with factory reset and rebuild before reconnection. CISA itself was among the victims: its Chemical Security Assessment Tool was intruded upon between 23 and 26 January 2024, an incident CISA later classified as major under FISMA.
The episode left two disputes that this paper assesses. Mandiant's forensic work with Ivanti found that UNC5325's attempt to survive a factory reset failed on any appliance that had been updated at least once; two days later CISA, citing its own lab research, warned that an actor "may be able to maintain root level persistence despite issuing factory resets". And the Integrity Checker Tool that Ivanti's guidance leaned on was shown by Volexity to have been tampered with on live victims, and characterised by Mandiant as a snapshot that cannot detect an actor who has cleaned up. Mandiant's later case studies showed why the appliance mattered: from it, UNC5221 reached a VMware vCenter server and UNC5330 used the appliance's LDAP bind account to take over an Active Directory domain.
Verification of Claims
-
Claim: Exploitation began in December 2023, before any public disclosure. → Verified → Volexity: "During the second week of December 2023, Volexity detected suspicious lateral movement on the network of one of its Network Security Monitoring service customers" [2]. Mandiant: exploitation "as early as December 2023" [4]; "since early December 2023" [7].
-
Claim: The two vulnerabilities chained give unauthenticated remote code execution. → Verified → Ivanti's advisory: "If CVE-2024-21887 is used in conjunction with CVE-2023-46805, exploitation does not require authentication and enables a threat actor to craft malicious requests and execute arbitrary commands on the system" [1]. CVSS 8.2 and 9.1 respectively per Ivanti and NVD [1][12].
-
Claim: Over 1,700 appliances were compromised. → Superseded → Volexity's 15 January scan of roughly 30,000 Connect Secure IP addresses found GIFTEDVISITOR on "over 1,700" [3]. On 18 January Volexity reported "an additional 368 compromised Ivanti Connect Secure VPN appliances, bringing the total count of systems infected by GIFTEDVISITOR to over 2,100" [8]. Both figures count one web shell family only; appliances backdoored with other tooling are not included.
-
Claim: Ivanti's Integrity Checker Tool is not sufficient to detect compromise. → Verified → Asserted by CISA and co-sealing agencies on 29 February 2024 [10]. Volexity had documented UTA0178 altering the built-in checker to "always indicate no findings, even if new or mismatched files were actually detected" [8]. Mandiant: "The ICT is a snapshot of the current state of the appliance and cannot necessarily detect threat actor activity if they have returned the appliance to a clean state" [5]. Mandiant also noted the external ICT detected BUSHWALK where the internal one could be tampered with [5].
-
Claim: An attacker may maintain root-level persistence despite a factory reset. → Assessed, Not Confirmed → CISA's wording is "may be able to", based on "independent research in a lab environment" [10]. The only published forensic case is Mandiant's: UNC5325's LITTLELAMB.WOOLTEA modified the factory-reset partition, but because that partition's kernel carries its own encryption key, "if the current running version and the factory reset deployment versions differ (i.e., the appliance or VM has been updated at least once), then /bin/losetup will fail to decrypt the factory reset partition … and thus the malware will not persist after factory reset". Mandiant and Ivanti examined an affected appliance after reset and found "no evidence of malware persistence" [6]. CISA's lab result was not published in enough detail to reconcile the two; the defensible reading is that persistence was attempted, failed on updated appliances, and is untested on never-updated ones.
-
Claim: The 10 January mitigation was bypassed. → Verified → Mandiant identified "a mitigation bypass technique that led to the deployment of a custom webshell tracked as BUSHWALK", circumventing the mitigation released on 10 January [5]. Mandiant tied the bypass to CVE-2024-21893, exploited by UNC5325 "as early as Jan. 19, 2024", twelve days before its disclosure, and noted it worked against "appliances with the XML mitigation released on Jan. 10, 2024" [6].
-
Claim: The actor is a Chinese state-sponsored group. → Assessed, Not Confirmed → Volexity: UTA0178 is "believed to be a Chinese nation-state-level threat actor" [2]. Mandiant on 11 January: "Mandiant had not linked this activity to a previously known group, nor do we currently have enough data to assess the origin" [4]; by 31 January "UNC5221 … a China-nexus espionage threat actor" on the basis of targeting, tooling overlaps and Chinese-language GitHub code [5]. UNC5325 is "associated with UNC3886" with moderate confidence [6]. No government has formally attributed the campaign. Earlier reporting that named APT41 or Winnti, including a previous ThreatPaper article, has no basis in either vendor's published analysis.
-
Claim: CISA's own systems were breached through these vulnerabilities. → Verified → CISA's Chemical Security Assessment Tool notification: the tool "was the target of a cybersecurity intrusion by a malicious actor from January 23 to 26, 2024", with potential unauthorised access to Top-Screen surveys, Security Vulnerability Assessments, Site Security Plans, Personnel Surety Program submissions and CSAT user accounts, and "no evidence of exfiltration" [11].
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| Early Dec 2023 | UNC5221 / UTA0178 | Zero-day exploitation of CVE-2023-46805 + CVE-2024-21887 begins | [4][7] |
| 2nd week Dec 2023 | Volexity | Lateral movement detected at a monitored customer; traced to Connect Secure appliance | [2] |
| 10 Jan 2024 | Ivanti | Advisory KB 000090122 and mitigation XML published; Volexity and Mandiant credited | [1] |
| 10 Jan 2024 | Volexity | Public report on UTA0178, GLASSTOKEN, GIFTEDVISITOR, ICT tampering | [2] |
| 11 Jan 2024 | Mandiant | "Cutting Edge" report: UNC5221, THINSPOOL, LIGHTWIRE, WIREFIRE, WARPWIRE, ZIPLINE | [4] |
| 11 Jan 2024 | Multiple actors | Widespread exploitation begins the day after disclosure | [3] |
| 12 Jan 2024 | NVD | CVE-2023-46805 and CVE-2024-21887 published | [12] |
| 15 Jan 2024 | Volexity | GIFTEDVISITOR found on more than 1,700 appliances worldwide | [3] |
| 18 Jan 2024 | Volexity | Count exceeds 2,100; ICT modified to always report clean; XMRig miners deployed by other actors | [8] |
| 19 Jan 2024 | CISA | Emergency Directive 24-01: apply mitigation by 22 Jan, run external ICT, report inventory | [9] |
| 19 Jan 2024 | UNC5325 | Begins exploiting CVE-2024-21893, bypassing the 10 Jan mitigation | [6] |
| 23–26 Jan 2024 | Unknown | Intrusion into CISA's Chemical Security Assessment Tool | [11] |
| 31 Jan 2024 | Ivanti | CVE-2024-21888 (CVSS 8.8) and CVE-2024-21893 (CVSS 8.2) disclosed; first patches; new mitigation | [6][12] |
| 31 Jan 2024 | Mandiant | "Cutting Edge, Part 2": BUSHWALK bypass, CHAINLINE, FRAMESTING; "China-nexus" assessment | [5] |
| 31 Jan 2024 | CISA | Supplemental Direction V1: disconnect all instances by 2 Feb; factory reset and rebuild before reconnection | [9] |
| 8 Feb 2024 | Ivanti | CVE-2024-22024 (XXE in SAML, CVSS 8.3) patched; NVD entry 13 Feb | [9][12] |
| 9 Feb 2024 | CISA | Supplemental Direction V2: apply 8 Feb update by 12 Feb | [9] |
| 27 Feb 2024 | Mandiant | "Cutting Edge, Part 3": UNC5325, LITTLELAMB.WOOLTEA, failed factory-reset persistence | [6] |
| 29 Feb 2024 | CISA, FBI, MS-ISAC, ACSC, NCSC-UK, CCCS, NCSC-NZ, CERT NZ | AA24-060B: ICT not sufficient; persistence through factory reset "may be" possible | [10] |
| 5 Apr 2024 | Mandiant | "Cutting Edge, Part 4": vCenter and Active Directory lateral movement case studies; UNC5266, UNC5330, UNC5337, UNC5291 | [7] |
Attack Anatomy
Initial access
CVE-2023-46805 let an unauthenticated request reach resources that should have required a session; CVE-2024-21887 let a request to a web component inject shell commands. Chained, a single unauthenticated HTTP exchange executed commands on the appliance as the web process [1][2]. From 19 January a second chain existed: CVE-2024-21893, an SSRF in the SAML component, combined with CVE-2024-21887, and it worked on appliances carrying the 10 January mitigation [6]. UNC5330 was using that second chain by February [7].
Persistence on the appliance
UNC5221's approach was to modify files the appliance already had rather than add new ones. THINSPOOL, a shell-script dropper, wrote the LIGHTWIRE Perl web shell into compcheckresult.cgi; WIREFIRE was a trojanised visits.py; WARPWIRE was JavaScript appended to lastauthserverused.js to capture plaintext credentials at login and send them to symantke[.]com; ZIPLINE was a passive backdoor hooking accept() in libsecure.so.1, waiting for a magic byte sequence [4]. Volexity's names for the same period were GLASSTOKEN (two versions, on Internet-facing and internal web servers) and GIFTEDVISITOR, reached via /api/v1/cav/client/visits [2]. After the mitigation, BUSHWALK went into querymanifest.cgi, activating when the platform parameter was SafariiOS; CHAINLINE and FRAMESTING were new Python files under the cav package, exposed at /api/v1/cav/client/health and /api/v1/cav/client/categories [5]. UNC5325 went deeper, loading LITTLELAMB.WOOLTEA (libchilkat.so) through a malicious SparkGateway plugin and attempting to trojanise the factory-reset partition itself [6].
Defence evasion
Volexity found the built-in Integrity Checker Tool altered to report no findings [8]; Mandiant warned that both vendors had seen tampering with the internal ICT and recommended the external one [5]. Command-and-control ran through compromised, out-of-support Cyberoam VPN appliances "domestic to the victims", so the traffic did not leave the country [4]. After deploying BUSHWALK, the actor was observed restoring the appliance to a clean state [5].
Collection and lateral movement
Post-disclosure, attackers stole "configuration data, web logs, and database files associated with accounts, session data", staging them in web-accessible folders for retrieval, partly automated [8]. Mandiant's case studies: UNC5221 used the ROOTROT web shell, then moved over the web console and SSH to a VMware vCenter server, created virtual machines and installed the BRICKSTORM Go backdoor under /home/vsphere-ui/vcli, masquerading as vami-http [7]. UNC5330 took the ldap-ivanti bind account from the appliance configuration, created a computer object, abused a vulnerable certificate template to obtain a domain administrator certificate, ran DCSync, and deployed TONERJAM and PHANTOMNET over WMI [7].
Loading diagram...
Threat Actor Profile
- Designations: UNC5221 (Mandiant); UTA0178 (Volexity). Follow-on clusters: UNC5325 (associated with UNC3886, moderate confidence), UNC5330, UNC5337 (possibly UNC5221 itself, medium confidence), UNC5266 (post-disclosure, Sliver and TERRIBLETEA), UNC5291 (associated with Volt Typhoon, moderate confidence) [6][7].
- Attribution and confidence: Volexity: "believed to be a Chinese nation-state-level threat actor" [2]. Mandiant: initially unassessed [4], then "China-nexus espionage" on targeting, infrastructure overlap and Chinese-language tooling [5]. No government attribution. The "APT41/Winnti" label in some coverage does not appear in either vendor's reporting.
- Motivation: Espionage. Targets after disclosure spanned "global government and military departments, national telecommunications companies, defense contractors" and Fortune 500 companies in technology, banking, finance and aerospace [3].
- Sophistication: Zero-day discovery and exploitation; malware families written for the appliance's own Perl and Python components; ICT tampering; domestic ORB-style C2; a mitigation bypass ready within nine days of the mitigation. UNC5325's factory-reset persistence attempt shows firmware-level understanding of the platform, even though it failed on updated appliances [6].
- Opportunists: Nearly two dozen source IPs attempting the correct URI pattern with poor operational security, and XMRig deployments, indicate the exploit spread well beyond the original actor within days [3][8].
MITRE ATT&CK (IDs checked on attack.mitre.org, 13 September 2026):
| ID | Technique | Evidence |
|---|---|---|
| T1190 | Exploit Public-Facing Application | CVE chain against the VPN gateway [1][10] |
| T1505.003 | Server Software Component: Web Shell | LIGHTWIRE, WIREFIRE, BUSHWALK, CHAINLINE, FRAMESTING, GIFTEDVISITOR [2][4][5] |
| T1554 | Compromise Host Software Binary | Malicious code inserted into legitimate appliance files [4] |
| T1556 | Modify Authentication Process | WARPWIRE capturing credentials in lastauthserverused.js [4] |
| T1685 | Disable or Modify Tools (formerly T1562.001) | Internal Integrity Checker Tool altered to report clean [8] |
| T1070 | Indicator Removal | Appliance restored to clean state after BUSHWALK deployment [5] |
| T1584.008 | Compromise Infrastructure: Network Devices | Out-of-support Cyberoam appliances as C2 [4] |
| T1078 | Valid Accounts | ldap-ivanti bind account, harvested VPN credentials [7][10] |
| T1005 | Data from Local System | Configuration, session database and logs staged for retrieval [8] |
| T1059.006 | Command and Scripting Interpreter: Python | CHAINLINE, FRAMESTING, WIREFIRE [5] |
| T1036.005 | Masquerading: Match Legitimate Name or Location | BRICKSTORM as vami-http [7] |
Technical Indicators
# Only indicators published by Volexity, Mandiant or CISA in the cited reports.
# Defanged. Full lists: Volexity GitHub repository; CISA AA24-060B.
domains:
- symantke[.]com # WARPWIRE credential exfiltration [4][10]
- gpoaccess[.]com # UTA0178 [2][10]
- webb-institute[.]com # UTA0178 [2][10]
ip_addresses:
- 206.189.208[.]156 # UTA0178 [2][10]
- 88.119.169[.]227 # CISA AA24-060B [10]
- 103.13.28[.]40 # CISA AA24-060B [10]
file_hashes:
- sha256: ed4b855941d6d7e07aacf016a2402c4c870876a050a4a547af194f5a9b47945f # WIREFIRE [10]
- md5: 3045f5b3d355a9ab26ab6f44cc831a83 # CHAINLINE health.py [5]
- md5: 465600cece80861497e8c1c86a07a23e # FRAMESTING category.py [5]
file_paths_modified_or_created:
- /home/webserver/htdocs/dana-na/auth/url_default/compcheckresult.cgi # LIGHTWIRE
- .../cav/api/resources/visits.py # WIREFIRE / GIFTEDVISITOR
- .../cav/api/resources/health.py # CHAINLINE (new file)
- .../cav/api/resources/category.py # FRAMESTING (new file)
- querymanifest.cgi # BUSHWALK
- lastauthserverused.js # WARPWIRE
- libsecure.so.1 # ZIPLINE
- libchilkat.so (SparkGateway plugin.jar) # LITTLELAMB.WOOLTEA / PITFUEL
hunting:
- GET /dana-na/auth/url_default/compcheckresult.cgi?comp=comp&compid=<obfuscated> # LIGHTWIRE
- POST /api/v1/cav/client/health # CHAINLINE
- POST /api/v1/cav/client/categories (legitimate endpoint accepts GET only) # FRAMESTING
- request parameter platform=SafariiOS to querymanifest.cgi # BUSHWALK
- ICS event SYS32042 "Integrity Checker Tool manifest file is bad" # ICT tamperingLegal and Regulatory Response
Vendor. Ivanti published KB 000090122 on 10 January 2024 with a mitigation XML, crediting Volexity and Mandiant; patches for the first versions on 31 January, further versions through February; a second mitigation on 31 January covering all four CVEs then known; CVE-2024-22024 patched 8 February [1][6][9].
CISA Emergency Directive 24-01 (19 January): mitigation by 22 January, external ICT immediately after, patches within 48 hours of release, inventory within a week. Supplemental Direction V1 (31 January): disconnect all Connect Secure and Policy Secure instances by 2 February; before reconnecting, export configuration, factory reset, rebuild, upgrade, re-import, revoke and reissue credentials; reset compromised domain passwords twice and revoke cloud tokens by 1 March. Supplemental Direction V2 (9 February, updated 4 March): apply the 8 February update by 12 February [9].
Joint advisory AA24-060B (29 February): CISA, FBI, MS-ISAC and the Australian, British, Canadian and New Zealand cyber agencies; states the ICT is not sufficient to detect compromise and that factory-reset persistence "may be" possible [10].
CISA as victim. CSAT intrusion 23–26 January 2024; classified a major incident under FISMA; notification to affected facilities [11].
Criminal or sanctions action. None public against UNC5221 or related clusters as of this writing.
Impact Assessment
- Appliances backdoored with GIFTEDVISITOR: Reported, more than 2,100 as of 18 January 2024 (Volexity scan) [8].
- Appliances scanned: Reported, approximately 30,000 Connect Secure IPs [3].
- Sectors: Confirmed, government, military, telecommunications, defence, technology, finance, aerospace, Fortune 500 [3].
- Confirmed downstream compromise: Confirmed in Mandiant case studies, VMware vCenter and an Active Directory domain [7]; CISA CSAT data potentially accessed, no exfiltration evidence [11].
- Federal operational impact: Confirmed, mandatory disconnection of every FCEB Connect Secure and Policy Secure instance from 2 February 2024 [9].
- Credential exposure: Confirmed mechanism (WARPWIRE) [4]; count Unknown.
- Financial loss: Unknown; no aggregate figure published.
Lessons and Defensive Recommendations
For SOC and IR teams
- Treat the appliance's own integrity checker as a witness that can be coerced. Run the external ICT from a clean host, and hunt for SYS32042 events and for POST requests to endpoints that only accept GET [5].
- Assume the appliance configuration was taken: rotate the LDAP bind account, VPN local accounts, API keys and certificates, and reset domain passwords twice as ED 24-01 required [7][9].
- Look sideways, not just at the appliance: vCenter logins from the appliance's address, new VMs, computer-object creation and certificate requests in AD in the window after exposure [7].
For platform and network owners
- Mitigations are not patches. The 10 January mitigation lasted nine days against the original actor [6]. Plan for disconnection when a vendor's fix is a configuration file.
- Edge devices that terminate authentication need the same logging and egress control as domain controllers. Domestic C2 through compromised neighbours defeats geo-based egress rules [4].
For leadership
- The federal government disconnected every instance of a product for weeks. A dependency on one remote-access gateway with no fallback is a business-continuity risk, not only a security one [9].
- Disputed technical questions (factory-reset persistence) should be resolved by evidence, not by the more alarming statement. Mandiant's forensic finding and CISA's lab warning are both in this paper so the reader can see exactly where the evidence stops [6][10].
For researchers
- The 1,700 figure was superseded within three days. Cite counts with their date and method [3][8].
Correction notice — 13 September 2026: This paper replaces an earlier ThreatPaper article on the same incident, published 2 September 2026 and withdrawn on 13 September 2026 after an internal audit. The earlier article contained placeholder file hashes, masked IP addresses, invented command-and-control domains, and attributions to Microsoft and Cisco Talos reports that do not exist, and it misdated the disclosure. Nothing from that article was carried over. Every statement here is sourced to a page fetched on 13 September 2026 and listed below.
Sources
- CVE-2023-46805 (Authentication Bypass) & CVE-2024-21887 (Command Injection) for Ivanti Connect Secure and Ivanti Policy Secure Gateways — Ivanti, KB 000090122, 10 January 2024
- Active Exploitation of Two Zero-Day Vulnerabilities in Ivanti Connect Secure VPN — Volexity, 10 January 2024
- Ivanti Connect Secure VPN Exploitation Goes Global — Volexity, 15 January 2024
- Cutting Edge: Suspected APT Targets Ivanti Connect Secure VPN in New Zero-Day Exploitation — Mandiant / Google Cloud, 11 January 2024
- Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation — Mandiant / Google Cloud, 31 January 2024
- Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts — Mandiant / Google Cloud, 27 February 2024
- Cutting Edge, Part 4: Ivanti Connect Secure VPN Post-Exploitation Lateral Movement Case Studies — Mandiant / Google Cloud, 5 April 2024
- Ivanti Connect Secure VPN Exploitation: New Observations — Volexity, 18 January 2024
- ED 24-01: Mitigate Ivanti Connect Secure and Ivanti Policy Secure Vulnerabilities — CISA, 19 January 2024, with Supplemental Direction V1 (31 January) and V2 (9 February 2024)
- AA24-060B: Threat Actors Exploit Multiple Vulnerabilities in Ivanti Connect Secure and Policy Secure Gateways — CISA, FBI, MS-ISAC, ACSC, NCSC-UK, CCCS, NCSC-NZ, CERT NZ, 29 February 2024
- Chemical Security Assessment Tool (CSAT) Ivanti Notification — CISA, 2024
- NVD entries: CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, CVE-2024-21893, CVE-2024-22024 — NIST National Vulnerability Database
Related Research
Anthropic's September threat report describes a Midnight Blizzard-linked operator running eight AI workflows — phishing, hotel Wi-Fi hijack, malware evasion — against 24 targets in Ukraine and Europe. Microsoft's CaptiveCrunch report, from the other side, lists four of the same domains.
A Russian national extradited from Cyprus faces trial over a 2016–17 campaign that used 225 fake accounts on a Santa Clara freelance platform to send Excel macros dropping the TeamViewer-abusing TVRAT. The unsealed indictment gives numbers the press release rounded away.
Cl0p exploited an unauthenticated deserialization flaw in PTC Windchill as a zero-day in June 2026, deployed a purpose-built web shell that decrypts the application's keystore, and named 43 manufacturers, including Shell, Philips and GE. It was the second such flaw in three months.