What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Malware found on Ivanti Connect Secure and Policy Secure appliances suggested that attackers were preparing to preserve access to selected victims even after security patches became available. Mandiant tied the campaign to exploitation of two vulnerabilities and described tools for deploying webshells, stealing credentials and maintaining backdoor access. That was an assessment of intent based on observed activity—not proof that every affected appliance stayed compromised after patching.

What happened in the Ivanti zero-day attacks

Ivanti disclosed two vulnerabilities on January 10, 2024: CVE-2023-46805, an authentication bypass, and CVE-2024-21887, a command injection flaw. Mandiant said it had observed exploitation as early as December 2023, before the public disclosure. The affected products were Ivanti Connect Secure VPN and Ivanti Policy Secure appliances. In combination, the flaws could enable an attacker to bypass authentication, run commands and progress to compromise elsewhere in a victim network.

Mandiant tracked the espionage actor behind the activity as UNC5221. Following exploitation, attackers deployed custom tools and, in some cases, altered legitimate files on the appliance to conceal or support their activity. The malware names in the investigation refer to attacker tools, not consumer security or malware-removal products.

Why the malware suggested preparation for patching

The significance was not simply that the attackers could exploit a zero-day. Their post-exploitation toolkit offered ways to establish footholds, return to appliances, collect credentials and potentially move through victim networks. Mandiant assessed that the activity was targeted: attackers intended to remain present on a subset of high-priority systems after patches were released.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
TP-Link ER605, Wired Gigabit VPN Router
  • 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
  • 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
  • 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
  • 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
  • Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q

Mandiant summarized its interpretation this way: “This indicates that these are not opportunistic attacks, and UNC5221 intended to maintain its presence on a subset of high priority targets that it compromised after a patch was inevitably released.” The statement describes Mandiant’s assessment of the operators’ intent. It does not establish that every compromised appliance retained an attacker, or that applying a patch by itself always left an attacker in place.

What each reported tool did

Tool Reported role
THINSPOOL A shell-script dropper used to write the LIGHTWIRE webshell into a legitimate Connect Secure file; Mandiant said it also supported persistence and detection evasion.
LIGHTWIRE and WIREFIRE Lightweight webshell footholds that enabled continued access to compromised appliances.
WARPWIRE A JavaScript credential stealer capable of capturing plaintext login credentials, potentially helping attackers with lateral movement or espionage.
ZIPLINE A passive backdoor with file-transfer, reverse-shell, proxy and tunneling capabilities.
PySoxy and BusyBox Additional tools used during post-exploitation; the cited account does not assign them a more specific role in its summary.

Historical timeline and attribution

  • December 2023: Mandiant’s earliest observed in-the-wild exploitation date.
  • January 10, 2024: Ivanti disclosed CVE-2023-46805 and CVE-2024-21887, according to Mandiant.
  • January 11, 2024: Singapore’s Cyber Security Agency (CSA) published an alert describing active exploitation and the patch schedule expected at that time: an initial version targeted for the week of January 22 and a final version targeted for the week of February 19. Those dates were historical forecasts, not current deadlines.
  • February 29, 2024: The initial version date of the joint government advisory with forensic and response guidance.

Attribution claims should remain distinct. Mandiant used the tracking name UNC5221 and did not publicly identify a government sponsor in the report described here. Contemporary SecurityWeek coverage said Volexity suspected a China connection under its own tracking label. These are separate assessments; they should not be collapsed into a definitive claim about sponsorship.

Rank #2
Netgate 1100 pfSense+ Security Gateway - Firewall, Router, VPN
  • BUSINESS READY - pfSense+ software updates included for product lifetime. Netgate TAC Lite technical support included. One year hardware warranty included.
  • COMPLETE - Pre-loaded with pfSense+ software to get up and running fast. Simply unbox it and start customizing for your secure edge networking needs. Free help with setup from our expert Technical Assistance Center (TAC) available 24/7/365.
  • POWERFUL - A dual core ARM Cortex-A53 1.2 GHz delivers near gigabit routing of common home iPerf3 traffic and in excess of 650 Mbps of firewall throughput.
  • COMPACT - Low power draw, a compact form factor, and silent operation allow it to run unnoticed when placed on a desktop, wall, or rack.
  • FLEXIBLE - Three (3) 1 GbE switched (WAN/LAN/OPT) ports allow you to configure three separate 1 GbE switched ports for upto a gigabit of bi-directional traffic.

How the defensive measures fit together

For organizations dealing with this incident, patching, integrity checking, monitoring and incident recovery address different problems. A file snapshot or successful patch is not, on its own, a complete investigation of earlier activity or possible compromise elsewhere in the network.

Measure What it can do Important limitation
Official remediation Apply Ivanti’s official patches and, where applicable to the period and appliance, follow the vendor’s mitigation guidance. Remediation does not by itself establish whether an attacker had already gained access or moved to other systems.
Integrity checking Ivanti described its enhanced external Integrity Checker Tool as taking an appliance file snapshot and detecting known changed or additional files. Ivanti cautioned that a snapshot may not reveal prior activity if the appliance has already been returned to a clean state. Treat it as one detection layer, not proof that no compromise occurred.
Continuous monitoring and threat hunting Look for ongoing activity on the appliance and investigate connected systems for signs of lateral movement. Appliance artifacts available for collection may be limited, so the investigation may need to include associated network systems.
Incident recovery Isolate affected hosts, reimage compromised systems and reset credentials that may have been exposed, following the joint government advisory. Response should be based on evidence and the organization’s incident process; an appliance cleanup alone may not address access or activity elsewhere.

Singapore CSA also advised affected organizations to isolate impacted appliances as much as possible, run Ivanti’s external Integrity Checker Tool and apply official patches when available. Its alert warned that the interim mitigation XML could affect appliance functionality, including SAML authentication. That warning concerned the interim mitigation described at the time; organizations should use current official vendor and government guidance for present-day decisions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
SonicWall TZ280 2.5 Gbps Next-Gen Firewall Appliance, HW Only
  • APPLIANCE ONLY: Hardware unit sold without a service subscription — security services, firmware updates and support are NOT included and must be purchased separately to activate protection.
  • PERFORMANCE: Up to 2.5 Gbps firewall inspection, 1 Gbps threat prevention and 1.2 Gbps IPSec VPN throughput driven by SonicWall's patented Reassembly-Free Deep Packet Inspection (RFDPI) engine.
  • CONNECTIVITY: 8x1GbE + 2x1G SFP in a desktop form factor; zero-touch deploy and manage on-box or via cloud Network Security Manager (NSM).
  • THREAT PROTECTION: SonicOS 8 delivers intrusion prevention, gateway anti-malware, application control, TLS/SSL decryption, Capture ATP multi-engine sandboxing (RTDMI) and reputation-based content & DNS filtering with an active service subscription.
  • BUILT FOR SMALL BUSINESS & BRANCH: Secure SD-WAN, IPSec and SSL VPN plus Zero-Trust Network Access through Cloud Secure Edge keep distributed sites and remote workers protected.

The joint advisory also cautioned that IP addresses listed in its guidance may be legitimate. They should not be blocked without analysis, since an address appearing in a list is not by itself proof of malicious activity.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What current operators should take from the incident

This is a historical account of a 2023–2024 campaign, not an operational runbook or a statement of current Ivanti patch status. Organizations using affected appliances should consult current Ivanti and government guidance, assess systems for evidence of compromise, and treat remediation and investigation as complementary work. The central lesson from the campaign is that patch availability does not erase the need to determine whether attackers established access before remediation.

Quick Recap

SaleBestseller No. 1
Bestseller No. 2
Netgate 1100 pfSense+ Security Gateway - Firewall, Router, VPN
Netgate 1100 pfSense+ Security Gateway - Firewall, Router, VPN
Ideal for AI security: Protect your AI workloads and data.
$299.00

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.