Skip to main content
Mallory
MalwareUsed by 1 actorExploits 2 CVEs

ZIPLINE

ZIPLINE is a passive backdoor associated with the China-nexus intrusion cluster UNC5221. Mandiant reported it among multiple custom malware families used by UNC5221 alongside LIGHTWIRE, THINSPOOL, WARPWIRE, and WIREFIRE during exploitation of Ivanti Connect Secure and Ivanti Policy Secure zero-day vulnerabilities CVE-2023-46805 and CVE-2024-21887. Reporting also describes UNC5221 as exploiting Ivanti zero-days to target government agencies and using custom malware including Spawnant and ZIPLINE.

Observed ZIPLINE capabilities include adding itself to the exclusion list for the Ivanti Connect Secure Integrity Checker Tool when the tar process is invoked with the --exclude parameter, creating a proxy server on compromised hosts, and communicating with command-and-control infrastructure using a custom binary protocol. The malware has been referenced in the context of UNC5221 operations against government and other organizations, and broader reporting on UNC5221 links the cluster to long-term espionage activity and compromises of edge or appliance technologies. Separately, Cisco Talos noted that the later PowMix campaign resembled an earlier "ZipLine" campaign in its use of ZIP-based payload distribution, scheduled task persistence, and Heroku for command-and-control, but the provided content does not establish that this campaign used the same ZIPLINE malware family.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

2 CVES
CVE-2023-46805Authentication Bypass in Ivanti Connect Secure and Policy Secure Web ComponentExploited in the wild

CVE-2023-46805 is an authentication bypass vulnerability in the web component of Ivanti Connect Secure (ICS), previously known as Pulse Connect Secure and Ivanti Policy Secure. This vulnerability allows an attacker to bypass control checks and access restricted resources.

via tenable blogtenable.com
CVE-2024-21887Command Injection in Ivanti Connect Secure and Policy Secure Web ComponentsExploited in the wild

CVE-2024-21887 is a command injection vulnerability in the web component of Ivanti ICS and Policy Secure that can be abused to execute arbitrary commands by an authenticated user.

via tenable blogtenable.com
THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
UNC5221

According to Mandiant, UNC5221 has “leveraged multiple custom malware families” which includes LIGHTWIRE, a webshell, THINSPOOL, a webshell dropper, WARPWIRE, a credential harvester, WIREFIRE, another webshell and ZIPLINE, a passive backdoor.

via tenable blogtenable.com
MITRE ATT&CK

Techniques & procedures

14 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1190Exploit Public-Facing ApplicationEvidence2

CVE-2024-21887 is a command injection vulnerability in the web component of Ivanti ICS and Policy Secure that can be abused to execute arbitrary commands by an authenticated user. | According to Ivanti and a blog by Volexity, these two vulnerabilities were exploited in the wild in a chained attack for unauthenticated remote code execution (RCE) as early as December 3, 2023. | CVE-2023-46805 is an authentication bypass vulnerability in the web component of Ivanti Connect Secure (ICS), previously known as Pulse Connect Secure and Ivanti Policy Secure. This vulnerability allows an attacker to bypass control checks and access restricted resources.

Execution

1 technique
T1059.004Unix ShellEvidence1
TacticExecution

Persistence

2 techniques
T1205Traffic SignalingEvidence1
T1505.003Web ShellEvidence1

"upload a web shell named SLAYSTYLE via the '/manager/text/deploy' endpoint"

Stealth

1 technique
T1205Traffic SignalingEvidence1

Discovery

2 techniques
T1057Process DiscoveryEvidence2
TacticDiscovery

The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.

T1083File and Directory DiscoveryEvidence1
TacticDiscovery
T1090ProxyEvidence1
T1090.001Internal ProxyEvidence2

APT41 used a tool called CLASSFON to covertly proxy network communications... BADCALL functions as a proxy server between the victim and C2 server... Sandworm Team's BCS-server tool can create an internal proxy server to redirect traffic...

T1095Non-Application Layer ProtocolEvidence1
T1105Ingress Tool TransferEvidence1
T1205Traffic SignalingEvidence1
T1573.001Symmetric CryptographyEvidence1

Other

3 techniques
T1562Impair DefensesEvidence2

The content repeatedly describes threat actors and malware disabling, stopping, uninstalling, or modifying antivirus, EDR, Windows Defender, AMSI, logging, and other security controls.

T1562.001Disable or Modify ToolsEvidence1
T1562.006Indicator BlockingEvidence1

BlackByte Ransomware 'adds .JS and .EXE extensions to the Microsoft Defender exclusion list'; PureCrypter 'executed Set-MpPreference -ExclusionPath'; QakBot 'modify the Registry to add its binaries to the Windows Defender exclusion list'; Raspberry Robin 'add an exception to Microsoft Defender that excludes the entire main drive'; StrongPity 'add directories used by the malware to the Windows Defender exclusions list'; XLoader 'can add the path of its executable to the Microsoft Defender exclusion list'; ZIPLINE 'can add itself to the exclusion list for the Ivanti Connect Secure Integrity Checker Tool.'

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities2

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping14

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.