FRAMESTING is a Python web shell targeting compromised Ivanti Connect Secure VPN appliances. It embeds malicious code in a legitimate component of the appliance’s CAV Python package, providing persistent, HTTP-accessible arbitrary command and Python code execution.
FRAMESTING accepts encrypted payloads through a cookie that mimics a legitimate VPN session cookie, or through compressed HTTP request-body content. Its processing includes Base64 decoding, AES decryption in ECB mode, zlib decompression, and execution through Python’s exec function. A shared cache retains execution results. The web shell can send and receive zlib-compressed data in HTTP POST requests. Embedding its functionality in an existing application component and disguising its communications as normal VPN traffic help conceal its presence and operation.
FRAMESTING was observed in the Cutting Edge activity involving exploitation of Ivanti appliances. This broader activity included the suspected China-nexus espionage actor UNC5221 and other uncategorized threat groups. FRAMESTING serves as a post-exploitation access mechanism on compromised network appliances.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
"...used 7-Zip to decode their Raindrop malware." / "...self-extracting RAR file to deliver modules..." / "...decompress a CAB file into executable content." | "...macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload." / "...involved the use of Base64 obfuscated scripts and commands." / "...deobfuscated Base64-encoded commands..."
Examples in the content include malware extracting or unpacking ZIP, RAR, CAB, tar.gz, and other archived content, such as 'Emotet has used a self-extracting RAR file to deliver modules to victims' and 'Rocke has extracted tar.gz files after downloading them from a C2 server.'
Examples include: "ChChes communicates to its C2 server over HTTP and embeds data within the Cookie HTTP header," "UPPERCUT has used HTTP for C2, including sending error codes in Cookie headers," and "GoldMax has used HTTPS and HTTP GET requests with custom HTTP cookies for C2."
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that embeds itself into a Python package on Ivanti Connect Secure VPN appliances for persistence.
Uses zlib-compressed data in HTTP POST requests for C2 communications.
Mimics Ivanti Connect Secure VPN session cookies (DSID) to make malicious traffic appear legitimate.
Web shell for Ivanti Connect Secure VPNs enabling arbitrary command execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.