WARPWIRE is a JavaScript credential-harvesting malware family associated with exploitation of Ivanti Connect Secure VPN appliances. It has been linked to intrusion activity tracked as UNC5221 and has also been observed in post-disclosure exploitation clusters involving Ivanti vulnerabilities including CVE-2023-46805, CVE-2024-21887, and CVE-2024-21893. The malware is designed to capture credentials from compromised appliances and transmit the stolen data to attacker-controlled infrastructure over HTTP using GET or POST requests. Observed variants can Base64-encode captured credentials before transmission. WARPWIRE is notable for embedding itself into legitimate files on compromised Ivanti Connect Secure systems, allowing it to blend into appliance components and support covert credential theft during post-exploitation. Its use fits broader espionage-oriented tradecraft seen in campaigns targeting edge devices for credential access and follow-on intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Mandiant created UNC5266 to track post-disclosure exploitation leading to deployment of Bishop Fox's SLIVER implant framework, a WARPWIRE variant, and a new malware family that Mandiant has named TERRIBLETEA.
Mandiant created UNC5266 to track post-disclosure exploitation leading to deployment of Bishop Fox's SLIVER implant framework, a WARPWIRE variant, and a new malware family that Mandiant has named TERRIBLETEA.
Table 3/4 describe multiple "WARPWIRE credential harvester variant" hashes for lastauthserverused.js and list "WARPWIRE C2 server" network indicators.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Mandiant created UNC5266 to track post-disclosure exploitation leading to deployment of Bishop Fox's SLIVER implant framework, a WARPWIRE variant, and a new malware family that Mandiant has named TERRIBLETEA.
According to Mandiant, UNC5221 has “leveraged multiple custom malware families” which includes LIGHTWIRE, a webshell, THINSPOOL, a webshell dropper, WARPWIRE, a credential harvester, WIREFIRE, another webshell and ZIPLINE, a passive backdoor.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
“assume that user and service account credentials stored within the affected Ivanti VPN appliances are likely compromised” / “able to exfiltrate domain administrator cleartext credentials… base64 encoded… and… NTLM password hashes”
CVE-2023-46805 is an authentication bypass vulnerability in the web component of Ivanti Connect Secure (ICS), previously known as Pulse Connect Secure and Ivanti Policy Secure. This vulnerability allows an attacker to bypass control checks and access restricted resources. | CVE-2024-21887 is a command injection vulnerability in the web component of Ivanti ICS and Policy Secure that can be abused to execute arbitrary commands by an authenticated user. | According to Ivanti and a blog by Volexity, these two vulnerabilities were exploited in the wild in a chained attack for unauthenticated remote code execution (RCE) as early as December 3, 2023.
Elise exfiltrates data using cookie values that are Base64-encoded... KONNI has used a custom base64 key to encode stolen data before exfiltration... Kevin can Base32 encode chunks of output files during exfiltration.
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A credential-harvesting malware family used by UNC5221 in activity tied to Ivanti exploitation.
Malware that Base64-encodes captured credentials with btoa() before sending them to command-and-control infrastructure.
Malware that Base64-encodes captured credentials with btoa() before sending them to command-and-control infrastructure.
Credential harvester written in JavaScript.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.