WIREFIRE, also known as GIFTEDVISITOR, is a Python web shell deployed on compromised Ivanti Connect Secure VPN appliances. It provides arbitrary command execution and file-transfer functionality, including uploading files to the appliance and downloading files. It can Base64-encode process output returned through command-and-control communications. The web shell is embedded in an existing Python component of the appliance, modifying legitimate application code to provide persistent attacker access.
WIREFIRE has been deployed following exploitation of CVE-2023-46805, an authentication bypass vulnerability, chained with CVE-2024-21887, a command injection vulnerability. This exploitation chain enables unauthenticated remote code execution on vulnerable appliances. The malware has been associated with activity tracked as UTA0178 and with the China-nexus espionage cluster UNC5221, including intrusions involving multiple web shells and other post-exploitation tools.
GIFTEDVISITOR infections were observed worldwide during widespread exploitation in January 2024, with more than 2,100 compromised Ivanti Connect Secure appliances identified by January 16. Affected organizations ranged from small businesses to Fortune 500 companies across government, military, telecommunications, defense, technology, finance, aerospace, and other sectors. WIREFIRE was also deployed during the intrusion into MITRE's Networked Experimentation, Research, and Virtualization Environment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Volexity detailed widespread exploitation of Ivanti Connect Secure VPN vulnerabilities CVE-2024-21887 and CVE-2023-46805. Following publication of proof-of-concept code, Volexity observed increased attacks and malicious payload deployment against vulnerable appliances. | On January 16, 2024, Volexity conducted a new scan for this backdoor and found an additional 368 compromised Ivanti Connect Secure VPN appliances, bringing the total count of systems infected by GIFTEDVISITOR to over 2,100.
Volexity detailed widespread exploitation of Ivanti Connect Secure VPN vulnerabilities CVE-2024-21887 and CVE-2023-46805, including broader scanning and exploitation using initially non-public exploits. Public proof-of-concept code appeared on January 16, 2024. | On January 16, 2024, Volexity conducted a new scan for this backdoor and found an additional 368 compromised Ivanti Connect Secure VPN appliances, bringing the total count of systems infected by GIFTEDVISITOR to over 2,100.
Threat actors are exploiting previously identified vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure gateways, including CVE-2023-46805 (CVSS 8.2), CVE-2024-21887 (CVSS 9.1) and CVE-2024-21893 (CVSS 8.1).
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
On January 16, 2024, Volexity conducted a new scan for this backdoor and found an additional 368 compromised Ivanti Connect Secure VPN appliances, bringing the total count of systems infected by GIFTEDVISITOR to over 2,100.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
They function as dormant backdoors, activated only when attackers submit specific HTTP requests containing commands or credentials.
the adversary executed suspicious Python scripts and /bin/sh commands from the /tmp directory
BEEFLUSH ... communicated with several internal IP addresses making POST requests.
The content repeatedly describes threat actors, malware, and campaigns using HTTP and/or HTTPS for command and control, including examples such as BlackEnergy communicating with C2 over HTTP POST requests and many other families using HTTP/S for C2.
The adversary uploaded a Python script, visits.py, that contained the WIREFIRE (aka GIFTEDVISITOR) web shell
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A webshell used to maintain access on compromised Ivanti Connect Secure VPN devices.
A Python web shell that supports file upload and arbitrary command execution, processing HTTP request bodies for a GIF delimiter and returning output after Base64 encoding, AES encryption, zlib compression, and padding.
A webshell variant used to backdoor compromised Ivanti Connect Secure VPN appliances, enabling persistent unauthorized access.
A variant webshell observed in widespread exploitation of Ivanti Connect Secure appliances.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.