ZIPLINE is a custom passive backdoor used by UNC5221, a suspected China-nexus cyberespionage cluster, on compromised Ivanti Connect Secure VPN appliances. It was deployed in operations involving exploitation of CVE-2023-46805, an authentication bypass vulnerability, and CVE-2024-21887, a command injection vulnerability, which together enable unauthenticated remote code execution. UNC5221's Ivanti exploitation activity has included targeting government agencies. ZIPLINE communicates with command-and-control infrastructure using a custom binary protocol and can create a proxy server on a compromised host. It also supports defense evasion by adding itself to the exclusion list used by the Ivanti Connect Secure Integrity Checker Tool when an archive-processing operation supplies an exclusion parameter. ZIPLINE forms part of UNC5221's custom malware arsenal alongside the LIGHTWIRE and WIREFIRE web shells, THINSPOOL dropper, and WARPWIRE credential harvester.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Following the successful exploitation of CVE-2023-46805 (authentication bypass) and CVE-2024-21887 (command injection), UNC5221 leveraged multiple custom malware families including the ZIPLINE passive backdoor, THINSPOOL dropper, LIGHTWIRE web shell, and WARPWIRE credential harvester. | UNC5221 leveraged multiple custom malware families including the ZIPLINE passive backdoor.
Following the successful exploitation of CVE-2023-46805 (authentication bypass) and CVE-2024-21887 (command injection), UNC5221 leveraged multiple custom malware families including the ZIPLINE passive backdoor, THINSPOOL dropper, LIGHTWIRE web shell, and WARPWIRE credential harvester. | UNC5221 leveraged multiple custom malware families including the ZIPLINE passive backdoor.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC5221 leveraged multiple custom malware families including the ZIPLINE passive backdoor.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
CVE-2024-21887 is a command injection vulnerability in the web component of Ivanti ICS and Policy Secure that can be abused to execute arbitrary commands by an authenticated user. | According to Ivanti and a blog by Volexity, these two vulnerabilities were exploited in the wild in a chained attack for unauthenticated remote code execution (RCE) as early as December 3, 2023. | CVE-2023-46805 is an authentication bypass vulnerability in the web component of Ivanti Connect Secure (ICS), previously known as Pulse Connect Secure and Ivanti Policy Secure. This vulnerability allows an attacker to bypass control checks and access restricted resources.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
The content repeatedly describes threat actors and malware disabling, stopping, uninstalling, or modifying antivirus, EDR, Windows Defender, AMSI, logging, and other security controls.
BlackByte Ransomware 'adds .JS and .EXE extensions to the Microsoft Defender exclusion list'; PureCrypter 'executed Set-MpPreference -ExclusionPath'; QakBot 'modify the Registry to add its binaries to the Windows Defender exclusion list'; Raspberry Robin 'add an exception to Microsoft Defender that excludes the entire main drive'; StrongPity 'add directories used by the malware to the Windows Defender exclusions list'; XLoader 'can add the path of its executable to the Microsoft Defender exclusion list'; ZIPLINE 'can add itself to the exclusion list for the Ivanti Connect Secure Integrity Checker Tool.'
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an earlier campaign similar to PowMix, sharing ZIP-based payload delivery, scheduled task persistence, and Heroku-based command-and-control techniques.
A malware family associated with UNC5221 in campaigns exploiting virtualization technologies and Ivanti zero-days.
Custom malware attributed to UNC5221, used in operations exploiting Ivanti zero-days against government agencies.
Custom malware used by UNC5221 in campaigns exploiting Ivanti zero-days against government agencies (functionality not described in the content).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.