Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications
What it means
CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.
Why it matters
L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.
Recommended actions
- Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.
- Verificare sistemi esposti, accessi remoti e versioni rispetto all'advisory ufficiale.
- Confermare che backup offline e immutabili siano separati e ripristinabili.
- Correlare TTP e IOC pubblicati con la telemetria autorizzata del proprio perimetro.
Potential operational benefits
- Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
- Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
- Validazione documentata della capacita di ripristino
Translation in progress
The official content is available in the original language. The Italian version will be published once automated checks are complete.
Text acquired from the source
Cybersecurity Advisory Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications Last Revised January 31, 2025 Alert Code AA25-022A Related topics: Organizations and Cyber Safety , Cyber Threats and Response , Incident Response Note: The CVEs in this advisory are unrelated to vulnerabilities (CVE-2025-0282 and CVE-2025-0283) in Ivanti’s Connect Secure, Policy Secure and ZTA Gateways. For more information on mitigating CVE -2025-0282 and CVE-2025-0283, see Ivanti Releases Security Updates for Connect Secure, Policy Secure, and ZTA Gateways . Summary The Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) are releasing this joint Cybersecurity Advisory in response to exploitation in September 2024 of vulnerabilities in Ivanti Cloud Service Appliances (CSA): CVE-2024-8963 , an administrative bypass vulnerability; CVE-2024-9379 , a SQL injection vulnerability; and CVE-2024-8190 and CVE-2024-9380 , remote code execution vulnerabilities. According to CISA and trusted third-party incident response data, threat actors chained the listed vulnerabilities to gain initial access, conduct remote code execution (RCE), obtain credentials, and implant webshells on victim networks. The actors’ primary exploit paths were two vulnerability chains. One exploit chain leveraged CVE-2024-8963 in conjunction with CVE-2024-8190 and CVE-2024-9380 and the other exploited CVE-2024-8963 and CVE-2024-9379. In one confirmed compromise, the actors moved laterally to two servers. All four vulnerabilities affect Ivanti CSA version 4.6x versions before 519, and two of the vulnerabilities (CVE-2024-9379 and CVE-2024-9380) affect CSA versions 5.0.1 and below; according to Ivanti, these CVEs have not been exploited in version 5.0.[ 1 ] Ivanti CS
Indicatori CISA verificabili
82 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.
Ultima verifica: 2026-09-26T04:09:01.177380+00:00
Scarica STIX 2.1Questo allegato contiene 4 indicatori incompleti o non interpretabili, conservati nell'originale ma esclusi dall'export operativo. I valori mancanti non sono stati dedotti.
| Tipo | Indicatore (non cliccabile) | File |
|---|---|---|
| domain-name | cri07nnrg958pkh6qhk0yrgy1e76p1od6[.]oast[.]fun | |
| domain-name | cri07nnrg958pkh6qhk0977u8c83jog6t[.]oast[.]fun | |
| MD5 | 1b20e9310ca815f9e2bd366fb94e147f | |
| MD5 | dd975310201079cacd4cde6facab8c1d | |
| MD5 | 86b62ffd33597fd635e01b95f08bb996 | |
| MD5 | f7f81ae880a17975f60e1e0fe1a4048b | |
| MD5 | 53c5b7d124f13039eb62409e1ec2089d | |
| ipv4-addr | 104[.]168[.]133[.]228 | |
| ipv4-addr | 149[.]154[.]176[.]41 | |
| MD5 | 30f57e14596f1bcad7cc4284d1af4684 | |
| MD5 | 62a611f0f1a418876b11c9df3b56885b | |
| MD5 | cacc30e2a5b2683e19e45dc4f191cebc | |
| MD5 | c7d20ca6fe596009afaeb725fec8635f | |
| MD5 | c2becc553b96ba27d60265d07ec3bd6c | |
| MD5 | aa69300617faab4eb39b789ebfeb5abe | |
| MD5 | 698a752ec1ca43237cb1dc791700afde | |
| MD5 | a50660fb31df96b3328640fdfbeea755 | |
| ipv4-addr | 45[.]141[.]215[.]17 | |
| MD5 | 061e5946c9595e560d64d5a8c65be49e | view.php |
| SHA-1 | cb6be7d4e741864817bd965ea4652364cccc9045 | view.php |
| SHA-256 | dcd04c0ac081fff41021d08cd882bcf70b696aa7824361ef23849e26f395148b | view.php |
| SSDEEP | 3:hTEd8x+QWp0SRJkHAhen:FE2x+QWuHoe | view.php |
| MD5 | 4895e11d30aa070fe45243a4e8b0e9dd | brokerDebug |
| SHA-1 | 20fecae6d41cce7a1f74313a3aeb97f7fa26895f | brokerDebug |
| SHA-256 | e35cf026057a3729387b7ecfb213ae62a611f0f1a418876b11c9df3b56885bed | brokerDebug |
| ipv4-addr | 64[.]176[.]49[.]160 | |
| ipv4-addr | 185[.]40[.]4[.]38 | |
| MD5 | c894f55c8fa9d92e2dd2c78172cff745 | |
| MD5 | f82847bccb621e6822a3947bc9ce9621 | |
| MD5 | ae51c891d2e895b5ca919d14edd42c26 | |
| ipv4-addr | 155[.]138[.]215[.]144 | |
| ipv4-addr | 188[.]172[.]229[.]15 | |
| ipv4-addr | 185[.]220[.]69[.]83 | |
| ipv4-addr | 185[.]199[.]103[.]196 | |
| ipv4-addr | 89[.]187[.]178[.]179 | |
| ipv4-addr | 216[.]73[.]162[.]56 | |
| ipv4-addr | 136[.]144[.]17[.]133 | |
| ipv4-addr | 136[.]144[.]17[.]145 | |
| ipv4-addr | 82[.]197[.]182[.]161 | |
| ipv4-addr | 154[.]213[.]185[.]230 | |
| ipv4-addr | 208[.]105[.]190[.]170 | |
| ipv4-addr | 185[.]40[.]4[.]95 | |
| ipv4-addr | 142[.]11[.]217[.]3 | |
| ipv4-addr | 134[.]195[.]90[.]71 | |
| MD5 | d13f71e51b38ffef6b9dc8efbed27615 | |
| MD5 | d88bfac2b43509abdc70308bef75e2a6 | |
| SHA-1 | 0f024f8487a9b908a8e81db7f6b4d85b70bbc212 | |
| SHA-256 | 3d0def685838f95a056d4fb5267b17ec3cc1c7a75fae0e4526b305cb964a1b88 | |
| MD5 | 78cc672218949a9ec87407ad3bcb5db6 | |
| SHA-1 | 25b79b4984a567b501e71fb3c43530a9b65d1c6e | |
| SHA-256 | 7cc4ed7bfd2a6f56ee1427a951bac36ad4e4e23fb66002d2befd2305e2d01bf3 | |
| domain-name | txt[.]xj[.]hk | |
| domain-name | gggg[.]oyr2ohrm[.]eyes[.]sh | |
| domain-name | ggg[.]oyr2ohrm[.]eyes[.]sh | |
| domain-name | gg[.]oyr2ohrm[.]eyes[.]sh | |
| url | https://file[.]io/frdZ9L18R7Nx | |
| url | https://file[.]io/RBKuU8gicWt | |
| url | https://file[.]io/E50vtqmJP5aa | |
| ipv4-addr | 203[.]160[.]72[.]174 | |
| ipv4-addr | 67[.]217[.]228[.]83 | |
| ipv4-addr | 108[.]174[.]199[.]200 | |
| domain-name | cdn[.]private-api[.]us[.]kg | |
| url | https://pan[.]xj[.]hk/d/6401646e701f5f47518ecef48a308a36/redis | |
| url | https://file[.]io/1zqvMYY1dpkk | |
| ipv4-addr | 107[.]173[.]89[.]16 | |
| ipv4-addr | 38[.]207[.]159[.]76 | |
| ipv4-addr | 23[.]236[.]66[.]97 | |
| ipv4-addr | 216[.]131[.]75[.]53 | |
| ipv4-addr | 205[.]169[.]39[.]11 | |
| ipv4-addr | 154[.]64[.]226[.]166 | |
| ipv4-addr | 142[.]171[.]217[.]195 | |
| ipv4-addr | 156[.]234[.]193[.]18 | |
| ipv4-addr | 98[.]101[.]25[.]30 | |
| ipv4-addr | 206[.]189[.]156[.]69 | |
| ipv4-addr | 192[.]42[.]116[.]210 | |
| MD5 | 60d5648d35bacf5c7aa713b2a0d267d3 | rar.exe |
| SHA-1 | a62af4ac233d914a25e79ec0705e2a187ebd7567 | rar.exe |
| SHA-256 | 4b16ea1b1273f8746cf399c71bfc1f5bff7378b5414b4ea044c55e0ee08c89d3 | rar.exe |
| SSDEEP | 12288:uPOMr1m/l86iW/YdYMl1trfDGbkg5eJmc1MziflRyHPTVL:uWMrE/a6iW/GYMljfDG4g5Xc+y7yHPTh | rar.exe |
| ipv4-addr | 203[.]160[.]86[.]69 | |
| domain-name | book[.]hacktricks[.]xyz | |
| domain-name | ip[.]sb |
Provenance
Allegato ufficiale CISA · 2025-01-21T18:42:13Z
SHA-512: c7080932f97c1ce2846cb6dcc9f33c7a38ed4dce5b255837f77f81d361d95e55a5b7c4c4bc93a6d8c01ce0c707927ecfd85ba0ffceefa0f02559105edf5846ff
- Source
- CISA Cybersecurity Advisories
- Publishing entity
- CISA
- Entity type
- National authority
- Area
- North America · US
- Original language
- en · translation in preparation
- Publication
- 31/01/2025 13:00
- Sharing
- TLP:CLEAR
- MITRE ATT&CK
- T1059, T1068, T1071.001, T1140, T1190, T1210, T1219, T1505.003, T1548.003, T1552.001, T1556, T1564.002, T1595.002
- CVE
- CVE-2025-0282, CVE-2025-0283, CVE-2024-8963, CVE-2024-9379, CVE-2024-8190, CVE-2024-9380, CVE-2024-9381
- Classification
- Medium
- Stated country
- US
Affected products and versions
The collector will check NVD and the available official vendor advisories.
Action indicated by the source
Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.
Official technical references
- https://www.cisa.gov/sites/default/files/2026-08/aa25-022a-threat-actors-chained-vulnerabilities-in-ivanti-cloud-service-applications_2.pdf
- https://www.cisa.gov/sites/default/files/2025-01/AA25-022A.stix__1.xml
- https://www.cisa.gov/sites/default/files/2025-01/AA25-022A-Threat-Actors-Chain-Vulnerabilities-In-Ivanti-Cloud-Service-Applications.stix__1.json