WIREFIRE is a web shell used in the exploitation of Ivanti Connect Secure VPN appliances. The content states that it was used during the broader Ivanti Connect Secure intrusion activity referred to as Cutting Edge, alongside other web shells including GLASSTOKEN, BUSHWALK, LIGHTWIRE, FRAMESTING, and GIFTEDVISITOR. WIREFIRE can modify the visits.py component of Ivanti Connect Secure VPNs to enable file download and arbitrary command execution, and it can Base64-encode process output sent to command-and-control infrastructure. Reporting in the provided content links related Ivanti exploitation to threat activity tracked by Mandiant as UNC5221, while Volexity attributed early exploitation of the underlying Ivanti vulnerabilities to UTA0178, which it assessed as a Chinese nation-state-level threat actor. The underlying campaigns involved exploitation of Ivanti Connect Secure vulnerabilities including CVE-2023-46805 and CVE-2024-21887, and victims ranged from small businesses to multiple Fortune 500 companies across various sectors. The content does not provide standalone WIREFIRE-specific indicators of compromise beyond its modification of visits.py and its Base64-encoded C2/process-output behavior.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-46805 is an authentication bypass vulnerability in the web component of Ivanti Connect Secure (ICS), previously known as Pulse Connect Secure and Ivanti Policy Secure. This vulnerability allows an attacker to bypass control checks and access restricted resources. | Volexity also published a follow-up blog post on January 15 into attacks involving CVE-2024-21887 and CVE-2023-46805. According to Volexity, exploitation of these flaws is now “widespread” globally, which includes the compromise of over 1,700 Ivanti Connect Secure (ICS) appliances, including the use of a variant of the webshell called GIFTEDVISITOR.
CVE-2024-21887 is a command injection vulnerability in the web component of Ivanti ICS and Policy Secure that can be abused to execute arbitrary commands by an authenticated user. | Volexity also published a follow-up blog post on January 15 into attacks involving CVE-2024-21887 and CVE-2023-46805. According to Volexity, exploitation of these flaws is now “widespread” globally, which includes the compromise of over 1,700 Ivanti Connect Secure (ICS) appliances, including the use of a variant of the webshell called GIFTEDVISITOR.
Table 1/3 list a Python package containing WIREFIRE and an HBI entry: "Cav-0.1-py3.6.egg" ... "WIREFIRE web shell".
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
According to Mandiant, UNC5221 has “leveraged multiple custom malware families” which includes LIGHTWIRE, a webshell, THINSPOOL, a webshell dropper, WARPWIRE, a credential harvester, WIREFIRE, another webshell and ZIPLINE, a passive backdoor.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
According to Ivanti and a blog by Volexity, these two vulnerabilities were exploited in the wild in a chained attack for unauthenticated remote code execution (RCE) as early as December 3, 2023. | CVE-2024-21887 is a command injection vulnerability in the web component of Ivanti ICS and Policy Secure that can be abused to execute arbitrary commands by an authenticated user. | CVE-2023-46805 is an authentication bypass vulnerability in the web component of Ivanti Connect Secure (ICS), previously known as Pulse Connect Secure and Ivanti Policy Secure. This vulnerability allows an attacker to bypass control checks and access restricted resources.
They function as dormant backdoors, activated only when attackers submit specific HTTP requests containing commands or credentials.
The content repeatedly describes threat actors, malware, and campaigns using HTTP and/or HTTPS for command and control, including examples such as BlackEnergy communicating with C2 over HTTP POST requests and many other families using HTTP/S for C2.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A webshell used to maintain access on compromised Ivanti Connect Secure VPN devices.
A webshell variant used to backdoor compromised Ivanti Connect Secure VPN appliances, enabling persistent unauthorized access.
A variant webshell observed in widespread exploitation of Ivanti Connect Secure appliances.
Malware that can Base64-encode process output sent to command-and-control infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.