Attackers widely compromised Ivanti Connect Secure and Policy Secure gateways by chaining authentication bypass CVE-2023-46805 with command injection CVE-2024-21887 to achieve unauthenticated remote command execution. Censys identified 26,095 internet-exposed Connect Secure hosts on January 22, 2024, including 412 carrying a JavaScript credential-stealing backdoor; Volexity separately reported GIFTEDVISITOR webshells on more than 2,100 devices. Akamai reported approximately 250,000 exploitation attempts daily following publication of exploit details, predominantly beaconing probes rather than confirmed compromises. Subsequent disclosures included privilege escalation CVE-2024-21888, actively exploited server-side request forgery CVE-2024-21893, associated with the DSLog backdoor, and SAML XML external entity vulnerability CVE-2024-22024. Scanning for the latter peaked at approximately 240,000 requests against 30,000 hosts, without establishing successful exploitation outcomes.
Retrospective investigations documented system-information and account-data theft, command-and-control implants, credential harvesting, lateral movement, remote-support tool installation, and Monero mining. Darktrace identified anomalous beaconing as early as December 21, 2023; researchers linked some compromises to likely state-backed espionage, while other activity appeared financially motivated. A possible subsequent double-extortion incident was not conclusively linked to the Ivanti intrusion. Northwave also documented build-specific hardcoded disk-encryption keys, enabling forensic recovery of appliance partitions. Patching alone is insufficient for suspected compromises: CISA directed affected federal civilian agencies to disconnect appliances, while vendor and incident-response guidance called for factory resets before patching, consecutive upgrades to prevent rollback into a compromised state, and updated interim mitigation where patches were unavailable. Organizations should isolate compromised gateways, revoke potentially exposed credentials, audit privileged accounts, and investigate connected systems; clean Integrity Checker Tool results do not rule out compromise. The incidents underscore the operational risk of internet-facing security appliances and the dependencies that can delay remediation.

See which actors are running it and whether you're in range.
31 events from the most recent confirmed update back to the earliest known activity.
Akamai observed approximately 240,000 scanning requests targeting 30,000 hosts, originating from more than 80 source IP addresses across 11 countries. The report did not establish successful compromise; scanning tapered off the following day.
A proof of concept for CVE-2024-22024 was published, followed by a surge in scanning observed by Akamai. The observed payloads resembled watchTowr's proof of concept and used blind, out-of-band interactions.
Ivanti published an advisory for an XML external entity vulnerability in the SAML component of Connect Secure and Policy Secure. Ivanti initially attributed discovery to internal testing and subsequently credited watchTowr with responsible disclosure.
Censys observed 26,095 internet-exposed Connect Secure hosts and identified 412 containing a modified JavaScript component that stole login credentials. The compromised hosts used 22 distinct credential-receiving callback URLs.
CISA directed Federal Civilian Executive Branch agencies to address the actively exploited Ivanti vulnerabilities. Required actions included implementing Ivanti recovery guidance, running its Integrity Checker Tool, and responding to evidence of compromise.
Akamai observed intense scanning beginning January 16, with exploitation attempts peaking within the first 24 hours after exploit disclosure. Its reported telemetry included approximately 250,000 attempts daily against more than 1,000 customers and 10,000 domains; most payloads tested command execution through beaconing rather than demonstrating confirmed compromise.
A proof of concept and complete exploitation details were published for chaining CVE-2023-46805 with CVE-2024-21887.
Darktrace's SOC and Threat Research teams began observing a significant volume of malicious activity targeting customer Ivanti appliances.
Ivanti published an advisory for CVE-2023-46805 and CVE-2024-21887 affecting Connect Secure and Policy Secure. Volexity and Mandiant also disclosed findings concerning the vulnerabilities, whose combination enables unauthenticated remote code execution.
Orange Cyberdefense CERT issued its first Critical threat advisory in more than 12 months concerning the Ivanti vulnerabilities.
The same appliance began beaconing to 103.13.28[.]40 on December 28, with activity continuing through December 29. Darktrace linked this address directly to post-exploitation activity involving the Ivanti vulnerability pair.
A customer case subsequently identified by Darktrace showed SSL beaconing to 154.223.20[.]226 beginning December 21 and continuing through December 28. Investigative reporting associated that infrastructure with Ivanti exploitation.
Volexity identified exploitation of CVE-2023-46805 and CVE-2024-21887 dating back to December 2023. The vulnerabilities could be chained to execute commands on Ivanti appliances without authentication.
Johannes B. Ullrich reported two honeypot requests: one attempted to chain CVE-2023-46805 and CVE-2024-21887 to execute the id command, while another attempted to trigger the GIFTEDVISITOR webshell. The requests demonstrate continued probing but do not establish successful exploitation.
A joint advisory from the U.S. government and international allies warned that attackers could deceive Ivanti's internal and external Integrity Checker Tools and potentially maintain root-level persistence despite factory resets. It recommended resetting exposed credentials, investigating additional malicious activity, and reassessing whether affected gateways should remain in enterprise environments.
Northwave's technical analysis found that examined LILO-based Ivanti systems used a modified loop-AES implementation with a hardcoded 16-byte key that varied by kernel build. Researchers documented methods for recovering decrypted partitions from live or emulated systems to support investigation.
In one customer environment, an attacker used valid credentials to access the Connect Secure VPN subnet, moved laterally using administrative tools, and exfiltrated data to put[.]io, likely with Rclone. Darktrace assessed this as possible preparation for double-extortion ransomware but could not confirm its relationship to the preceding Ivanti compromise.
Darktrace observed an attacker installing a Monero cryptominer downloaded from 192.252.183[.]116. Associated artifacts included a script apparently intended to terminate existing miners and a configuration referencing auto.3pool[.]org:19999.
Darktrace observed suspected JavaScript credential harvesters sending login credentials to likely compromised websites. Some attackers used valid credentials for RDP lateral movement from compromised Ivanti appliances, with subsequent traffic indicating installation of SimpleHelp.
Darktrace observed compromised appliances uploading hundreds of megabytes of apparent system information to 139.180.194[.]132. Attackers also downloaded likely Rust-based ELF payloads from AWS-hosted infrastructure and established subsequent command-and-control connections.
Orange Cyberdefense CERT's exploratory scans identified 24,986 exposed Ivanti devices, including 3,254 vulnerable devices, 684 compromised devices, and 680 devices leaking sensitive data.
CISA added the Ivanti server-side request forgery vulnerability CVE-2024-21893 to its Known Exploited Vulnerabilities catalog.
CISA directed Federal Civilian Executive Branch agencies to disconnect all Connect Secure and Policy Secure instances from agency networks. Related guidance urged agencies to factory-reset their appliances.
Volexity identified the GIFTEDVISITOR web shell on more than 2,100 compromised Ivanti devices. UTA0178 exfiltrated account information, session data, and other information from globally distributed victims, including Fortune 500 companies.
Ivanti provided mitigation and recovery guidance while official patches for the original vulnerability pair were unavailable. Customers were advised to use its Integrity Checker Tool to look for signs of compromise.
Volexity and Mandiant tracked compromise clusters as UTA0178 and UNC5221, respectively, and associated them with a likely espionage-motivated, state-linked actor. The compromises involved web shells and JavaScript credential harvesters.
A FortiGuard update reported that Skibidi botnet malware targets CVE-2024-21887 in Ivanti Connect Secure.
CISA released a cybersecurity advisory concerning threat actors exploiting vulnerabilities in Ivanti Connect Secure and Policy Secure gateways.
Orange Cyberdefense reported that attackers were exploiting CVE-2024-21893 to install a backdoor named DSLog.
Ivanti released patches for CVE-2023-46805 and CVE-2024-21887 in selected Connect Secure releases and ZTA 22.6R1.3. Ivanti recommended factory-resetting appliances before applying the patches.
Ivanti disclosed CVE-2024-21893, a server-side request forgery vulnerability, and CVE-2024-21888, a privilege-escalation vulnerability, affecting Connect Secure, Policy Secure, and ZTA gateways. Reporting identified active exploitation of CVE-2024-21893 and a new interim mitigation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 201 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
12 references tracked. Mallory keeps watching after this page renders.
darktrace.com
Open sourcenorthwave-cybersecurity.com
Open sourceisc.sans.edu
Open sourceorangecyberdefense.com
Open sourceorangecyberdefense.com
Open sourcecensys.com
Open sourcefortiguard.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.