LIGHTWIRE is a Perl web shell used to execute commands and maintain persistent access on compromised Ivanti Connect Secure VPN appliances. It embeds malicious code within a legitimate CGI component, creating a remotely accessible execution mechanism. Its command handler Base64-decodes and RC4-decrypts attacker-supplied request data, then executes the decrypted payload through Perl eval.
LIGHTWIRE is associated with UNC5221, a suspected China-nexus espionage actor that exploited Ivanti appliances beginning in December 2023. It was deployed in intrusions involving the chaining of CVE-2023-46805, an authentication bypass vulnerability, and CVE-2024-21887, a command injection vulnerability, to obtain unauthenticated remote code execution. LIGHTWIRE variants were also deployed after attackers developed ways to bypass Ivanti’s initial January 2024 mitigations. Its role is persistent post-exploitation access and command execution on enterprise remote-access appliances.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Following the successful exploitation of CVE-2023-46805 (authentication bypass) and CVE-2024-21887 (command injection), UNC5221 leveraged multiple custom malware families including the ZIPLINE passive backdoor, THINSPOOL dropper, LIGHTWIRE web shell, and WARPWIRE credential harvester. | UNC5221 leveraged multiple custom malware families including ... LIGHTWIRE web shell.
Following the successful exploitation of CVE-2023-46805 (authentication bypass) and CVE-2024-21887 (command injection), UNC5221 leveraged multiple custom malware families including the ZIPLINE passive backdoor, THINSPOOL dropper, LIGHTWIRE web shell, and WARPWIRE credential harvester. | UNC5221 leveraged multiple custom malware families including ... LIGHTWIRE web shell.
Threat actors are exploiting previously identified vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure gateways, including CVE-2023-46805 (CVSS 8.2), CVE-2024-21887 (CVSS 9.1) and CVE-2024-21893 (CVSS 8.1).
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC5221 leveraged multiple custom malware families including ... LIGHTWIRE web shell.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
LIGHTWIRE can imbed itself into the legitimate compcheckresult.cgi component of Ivanti Connect Secure VPNs to enable command execution.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom webshell malware family leveraged by UNC5221 in activity related to Ivanti exploitation.
Malware that embeds into a legitimate Ivanti Connect Secure VPN component to enable command execution.
Web shell for Ivanti Secure Connect VPNs enabling command execution and persistence.
A web shell included in the indicators for the Ivanti exploitation activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.