EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Ransomware

Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications

Official source
EudorIA operational summary

What it means

Priority 95/100

CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.

Why it matters

L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.

Potential operational benefits

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
AudienceITSOCCISOManagement
Information centre

Translation in progress

CISA

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Cybersecurity Advisory Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications Last Revised January 31, 2025 Alert Code AA25-022A Related topics: Organizations and Cyber Safety , Cyber Threats and Response , Incident Response Note: The CVEs in this advisory are unrelated to vulnerabilities (CVE-2025-0282 and CVE-2025-0283) in Ivanti’s Connect Secure, Policy Secure and ZTA Gateways. For more information on mitigating CVE -2025-0282 and CVE-2025-0283, see Ivanti Releases Security Updates for Connect Secure, Policy Secure, and ZTA Gateways . Summary The Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) are releasing this joint Cybersecurity Advisory in response to exploitation in September 2024 of vulnerabilities in Ivanti Cloud Service Appliances (CSA): CVE-2024-8963 , an administrative bypass vulnerability; CVE-2024-9379 , a SQL injection vulnerability; and CVE-2024-8190 and CVE-2024-9380 , remote code execution vulnerabilities. According to CISA and trusted third-party incident response data, threat actors chained the listed vulnerabilities to gain initial access, conduct remote code execution (RCE), obtain credentials, and implant webshells on victim networks. The actors’ primary exploit paths were two vulnerability chains. One exploit chain leveraged CVE-2024-8963 in conjunction with CVE-2024-8190 and CVE-2024-9380 and the other exploited CVE-2024-8963 and CVE-2024-9379. In one confirmed compromise, the actors moved laterally to two servers. All four vulnerabilities affect Ivanti CSA version 4.6x versions before 519, and two of the vulnerabilities (CVE-2024-9379 and CVE-2024-9380) affect CSA versions 5.0.1 and below; according to Ivanti, these CVEs have not been exploited in version 5.0.[ 1 ] Ivanti CS

Indicatori CISA verificabili

82 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Copertura parziale: sono mostrati solo gli indicatori verificati e interpretabili. 1 allegati richiedono ancora verifica o un formato supportato.

Ultima verifica: 2026-09-26T04:09:01.177380+00:00

Scarica STIX 2.1

Questo allegato contiene 4 indicatori incompleti o non interpretabili, conservati nell'originale ma esclusi dall'export operativo. I valori mancanti non sono stati dedotti.

TipoIndicatore (non cliccabile)File
domain-namecri07nnrg958pkh6qhk0yrgy1e76p1od6[.]oast[.]fun
domain-namecri07nnrg958pkh6qhk0977u8c83jog6t[.]oast[.]fun
MD51b20e9310ca815f9e2bd366fb94e147f
MD5dd975310201079cacd4cde6facab8c1d
MD586b62ffd33597fd635e01b95f08bb996
MD5f7f81ae880a17975f60e1e0fe1a4048b
MD553c5b7d124f13039eb62409e1ec2089d
ipv4-addr104[.]168[.]133[.]228
ipv4-addr149[.]154[.]176[.]41
MD530f57e14596f1bcad7cc4284d1af4684
MD562a611f0f1a418876b11c9df3b56885b
MD5cacc30e2a5b2683e19e45dc4f191cebc
MD5c7d20ca6fe596009afaeb725fec8635f
MD5c2becc553b96ba27d60265d07ec3bd6c
MD5aa69300617faab4eb39b789ebfeb5abe
MD5698a752ec1ca43237cb1dc791700afde
MD5a50660fb31df96b3328640fdfbeea755
ipv4-addr45[.]141[.]215[.]17
MD5061e5946c9595e560d64d5a8c65be49eview.php
SHA-1cb6be7d4e741864817bd965ea4652364cccc9045view.php
SHA-256dcd04c0ac081fff41021d08cd882bcf70b696aa7824361ef23849e26f395148bview.php
SSDEEP3:hTEd8x+QWp0SRJkHAhen:FE2x+QWuHoeview.php
MD54895e11d30aa070fe45243a4e8b0e9ddbrokerDebug
SHA-120fecae6d41cce7a1f74313a3aeb97f7fa26895fbrokerDebug
SHA-256e35cf026057a3729387b7ecfb213ae62a611f0f1a418876b11c9df3b56885bedbrokerDebug
ipv4-addr64[.]176[.]49[.]160
ipv4-addr185[.]40[.]4[.]38
MD5c894f55c8fa9d92e2dd2c78172cff745
MD5f82847bccb621e6822a3947bc9ce9621
MD5ae51c891d2e895b5ca919d14edd42c26
ipv4-addr155[.]138[.]215[.]144
ipv4-addr188[.]172[.]229[.]15
ipv4-addr185[.]220[.]69[.]83
ipv4-addr185[.]199[.]103[.]196
ipv4-addr89[.]187[.]178[.]179
ipv4-addr216[.]73[.]162[.]56
ipv4-addr136[.]144[.]17[.]133
ipv4-addr136[.]144[.]17[.]145
ipv4-addr82[.]197[.]182[.]161
ipv4-addr154[.]213[.]185[.]230
ipv4-addr208[.]105[.]190[.]170
ipv4-addr185[.]40[.]4[.]95
ipv4-addr142[.]11[.]217[.]3
ipv4-addr134[.]195[.]90[.]71
MD5d13f71e51b38ffef6b9dc8efbed27615
MD5d88bfac2b43509abdc70308bef75e2a6
SHA-10f024f8487a9b908a8e81db7f6b4d85b70bbc212
SHA-2563d0def685838f95a056d4fb5267b17ec3cc1c7a75fae0e4526b305cb964a1b88
MD578cc672218949a9ec87407ad3bcb5db6
SHA-125b79b4984a567b501e71fb3c43530a9b65d1c6e
SHA-2567cc4ed7bfd2a6f56ee1427a951bac36ad4e4e23fb66002d2befd2305e2d01bf3
domain-nametxt[.]xj[.]hk
domain-namegggg[.]oyr2ohrm[.]eyes[.]sh
domain-nameggg[.]oyr2ohrm[.]eyes[.]sh
domain-namegg[.]oyr2ohrm[.]eyes[.]sh
urlhttps://file[.]io/frdZ9L18R7Nx
urlhttps://file[.]io/RBKuU8gicWt
urlhttps://file[.]io/E50vtqmJP5aa
ipv4-addr203[.]160[.]72[.]174
ipv4-addr67[.]217[.]228[.]83
ipv4-addr108[.]174[.]199[.]200
domain-namecdn[.]private-api[.]us[.]kg
urlhttps://pan[.]xj[.]hk/d/6401646e701f5f47518ecef48a308a36/redis
urlhttps://file[.]io/1zqvMYY1dpkk
ipv4-addr107[.]173[.]89[.]16
ipv4-addr38[.]207[.]159[.]76
ipv4-addr23[.]236[.]66[.]97
ipv4-addr216[.]131[.]75[.]53
ipv4-addr205[.]169[.]39[.]11
ipv4-addr154[.]64[.]226[.]166
ipv4-addr142[.]171[.]217[.]195
ipv4-addr156[.]234[.]193[.]18
ipv4-addr98[.]101[.]25[.]30
ipv4-addr206[.]189[.]156[.]69
ipv4-addr192[.]42[.]116[.]210
MD560d5648d35bacf5c7aa713b2a0d267d3rar.exe
SHA-1a62af4ac233d914a25e79ec0705e2a187ebd7567rar.exe
SHA-2564b16ea1b1273f8746cf399c71bfc1f5bff7378b5414b4ea044c55e0ee08c89d3rar.exe
SSDEEP12288:uPOMr1m/l86iW/YdYMl1trfDGbkg5eJmc1MziflRyHPTVL:uWMrE/a6iW/GYMljfDG4g5Xc+y7yHPThrar.exe
ipv4-addr203[.]160[.]86[.]69
domain-namebook[.]hacktricks[.]xyz
domain-nameip[.]sb

Provenance

Allegato ufficiale CISA · 2025-01-21T18:42:13Z

SHA-512: c7080932f97c1ce2846cb6dcc9f33c7a38ed4dce5b255837f77f81d361d95e55a5b7c4c4bc93a6d8c01ce0c707927ecfd85ba0ffceefa0f02559105edf5846ff

Source
CISA Cybersecurity Advisories
Publishing entity
CISA
Entity type
National authority
Area
North America · US
Original language
en · translation in preparation
Publication
31/01/2025 13:00
Sharing
TLP:CLEAR
MITRE ATT&CK
T1059, T1068, T1071.001, T1140, T1190, T1210, T1219, T1505.003, T1548.003, T1552.001, T1556, T1564.002, T1595.002
CVE
CVE-2025-0282, CVE-2025-0283, CVE-2024-8963, CVE-2024-9379, CVE-2024-8190, CVE-2024-9380, CVE-2024-9381
Classification
Medium
Stated country
US
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Action indicated by the source

Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.

Official technical references

Open the original source