Cutting Edge is a named intrusion campaign associated with exploitation of Ivanti Connect Secure VPN appliances, including activity tied to CVE-2023-46805 and CVE-2024-21887. The operators demonstrated post-compromise tradecraft focused on scripted execution, host discovery, credential access, and anti-forensics. Observed behavior included use of Perl-based tooling to deploy the THINSPOOL shell-script dropper and enumerate host data, as well as use of ENUM4LINUX for discovery against Windows and Samba environments. The campaign also involved access to and mounting of virtual hard disk backups to extract the Active Directory database for credential theft. Defense-evasion and cleanup actions were prominent: the operators cleared logs, deleted temporary staging artifacts used to hold stolen data, and restored compromised systems to a clean state in order to bypass vendor mitigations and reduce forensic visibility. The available information supports characterization of Cutting Edge as a post-exploitation-focused campaign with strong emphasis on stealth, discovery, and credential acquisition, but does not provide high-confidence attribution to a specific named threat actor or state sponsor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Deleted temporary files holding stolen configuration and cache data on compromised Ivanti Connect Secure VPNs.
Activity cluster in which operators cleared logs and restored compromised systems to bypass mitigations.
Activity cluster using Perl scripts to deploy a shell script dropper and enumerate host data.
Activity cluster involving Perl scripts for THINSPOOL deployment and host enumeration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.