WARPWIRE is a JavaScript credential harvester deployed on compromised Ivanti Connect Secure VPN appliances. It is embedded in legitimate appliance web resources and captures usernames and passwords entered into login forms. Captured credentials can be Base64-encoded using the JavaScript btoa() function and transmitted to attacker-controlled servers through HTTP GET or POST requests. Harvested data can also include the login page URL or hostname, providing context for the stolen credentials.
WARPWIRE is associated with UNC5221, a suspected China-nexus espionage actor whose exploitation of Ivanti appliances began in December 2023. The actor deployed it alongside custom web shells, droppers, and backdoors during intrusions involving the CVE-2023-46805 authentication bypass and CVE-2024-21887 command injection vulnerabilities. UNC5266 also deployed a WARPWIRE variant alongside SLIVER and TERRIBLETEA during exploitation following the January 2024 public disclosure of the Ivanti vulnerabilities. WARPWIRE functions as a credential-theft component of these appliance compromises rather than as the initial exploitation mechanism.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Following the successful exploitation of CVE-2023-46805 (authentication bypass) and CVE-2024-21887 (command injection), UNC5221 leveraged multiple custom malware families including the ZIPLINE passive backdoor, THINSPOOL dropper, LIGHTWIRE web shell, and WARPWIRE credential harvester. | UNC5221 leveraged multiple custom malware families including ... WARPWIRE credential harvester.
Following the successful exploitation of CVE-2023-46805 (authentication bypass) and CVE-2024-21887 (command injection), UNC5221 leveraged multiple custom malware families including the ZIPLINE passive backdoor, THINSPOOL dropper, LIGHTWIRE web shell, and WARPWIRE credential harvester. | UNC5221 leveraged multiple custom malware families including ... WARPWIRE credential harvester.
Threat actors are exploiting previously identified vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure gateways, including CVE-2023-46805 (CVSS 8.2), CVE-2024-21887 (CVSS 9.1) and CVE-2024-21893 (CVSS 8.1).
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC5221 leveraged multiple custom malware families including ... WARPWIRE credential harvester.
UNC5266 deployed a WARPWIRE variant alongside SLIVER and TERRIBLETEA following exploitation.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Threat actors leverage compromised accounts to laterally move within internal systems via RDP, SBD, and SSH.
CVE-2023-46805 is an authentication bypass vulnerability in the web component of Ivanti Connect Secure (ICS), previously known as Pulse Connect Secure and Ivanti Policy Secure. This vulnerability allows an attacker to bypass control checks and access restricted resources. | CVE-2024-21887 is a command injection vulnerability in the web component of Ivanti ICS and Policy Secure that can be abused to execute arbitrary commands by an authenticated user. | According to Ivanti and a blog by Volexity, these two vulnerabilities were exploited in the wild in a chained attack for unauthenticated remote code execution (RCE) as early as December 3, 2023.
Multiple IP addresses and domains are identified as "WARPWIRE variant C2 server" or "WARPWIRE C2 server."
Elise exfiltrates data using cookie values that are Base64-encoded... KONNI has used a custom base64 key to encode stolen data before exfiltration... Kevin can Base32 encode chunks of output files during exfiltration.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A credential-harvesting malware family used by UNC5221 in activity tied to Ivanti exploitation.
Malware that Base64-encodes captured credentials with btoa() before sending them to command-and-control infrastructure.
Malware that Base64-encodes captured credentials with btoa() before sending them to command-and-control infrastructure.
Credential harvester written in JavaScript.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.