DslogdRAT is a remote access trojan observed in intrusions involving Ivanti Connect Secure appliances. It has been deployed after exploitation of the critical Ivanti Connect Secure vulnerability CVE-2025-0282, including zero-day activity targeting organizations in Japan beginning in late 2024. In reported attack chains, adversaries first installed a Perl web shell on the compromised appliance and then used it to deliver DslogdRAT as a follow-on payload.
Once active, DslogdRAT establishes a socket-based connection to attacker-controlled infrastructure, transmits basic host information, and awaits tasking. Its supported functions include remote shell command execution, file upload and download, and proxying network traffic through the infected system. These capabilities make it suitable for sustained post-compromise access and operator-driven follow-on activity.
DslogdRAT has been discussed alongside other malware families used in exploitation of Ivanti Connect Secure flaws, including SPAWNCHIMERA and related SPAWN ecosystem components. Reporting has linked the broader exploitation of these Ivanti vulnerabilities to China-nexus intrusion activity, but available information does not conclusively attribute DslogdRAT itself to the same specific campaign or actor cluster. The malware is associated with attacks against organizations using Ivanti Connect Secure, affecting both private-sector and government environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"...installed by exploiting a zero-day vulnerability at that time, CVE-2025-0282, during attacks against organizations in Japan around December 2024..."; "CVE-2025-0282 refers to a critical security flaw in ICS that could allow unauthenticated remote code execution. It was addressed by Ivanti in early January 2025." | Cybersecurity researchers are warning about a new malware called DslogdRAT that's installed following the exploitation of a now-patched security flaw in Ivanti Connect Secure (ICS).
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in related articles; not part of the APT-C-60 SpyGlace campaign described in this content.
Related articles DslogdRAT Malware Installed in Ivanti Connect Secure
RAT installed (with a web shell) after exploitation of Ivanti Connect Secure zero-day CVE-2025-0282 in attacks in Japan (Dec 2024).
DslogdRAT is a remote access trojan delivered via exploitation of Ivanti Connect Secure vulnerabilities. Specific details are not provided in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.