Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications
Cosa significa
CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.
Perché conta
L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.
Azioni consigliate
- Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.
- Verificare sistemi esposti, accessi remoti e versioni rispetto all'advisory ufficiale.
- Confermare che backup offline e immutabili siano separati e ripristinabili.
- Correlare TTP e IOC pubblicati con la telemetria autorizzata del proprio perimetro.
Benefici operativi potenziali
- Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
- Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
- Validazione documentata della capacita di ripristino
Traduzione in elaborazione
Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.
Testo acquisito dalla fonte
Cybersecurity Advisory Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications Last Revised January 31, 2025 Alert Code AA25-022A Related topics: Organizations and Cyber Safety , Cyber Threats and Response , Incident Response Note: The CVEs in this advisory are unrelated to vulnerabilities (CVE-2025-0282 and CVE-2025-0283) in Ivanti’s Connect Secure, Policy Secure and ZTA Gateways. For more information on mitigating CVE -2025-0282 and CVE-2025-0283, see Ivanti Releases Security Updates for Connect Secure, Policy Secure, and ZTA Gateways . Summary The Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) are releasing this joint Cybersecurity Advisory in response to exploitation in September 2024 of vulnerabilities in Ivanti Cloud Service Appliances (CSA): CVE-2024-8963 , an administrative bypass vulnerability; CVE-2024-9379 , a SQL injection vulnerability; and CVE-2024-8190 and CVE-2024-9380 , remote code execution vulnerabilities. According to CISA and trusted third-party incident response data, threat actors chained the listed vulnerabilities to gain initial access, conduct remote code execution (RCE), obtain credentials, and implant webshells on victim networks. The actors’ primary exploit paths were two vulnerability chains. One exploit chain leveraged CVE-2024-8963 in conjunction with CVE-2024-8190 and CVE-2024-9380 and the other exploited CVE-2024-8963 and CVE-2024-9379. In one confirmed compromise, the actors moved laterally to two servers. All four vulnerabilities affect Ivanti CSA version 4.6x versions before 519, and two of the vulnerabilities (CVE-2024-9379 and CVE-2024-9380) affect CSA versions 5.0.1 and below; according to Ivanti, these CVEs have not been exploited in version 5.0.[ 1 ] Ivanti CS
Indicatori CISA verificabili
82 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.
Ultima verifica: 2026-09-26T04:09:01.177380+00:00
Scarica STIX 2.1Questo allegato contiene 4 indicatori incompleti o non interpretabili, conservati nell'originale ma esclusi dall'export operativo. I valori mancanti non sono stati dedotti.
| Tipo | Indicatore (non cliccabile) | File |
|---|---|---|
| domain-name | cri07nnrg958pkh6qhk0yrgy1e76p1od6[.]oast[.]fun | |
| domain-name | cri07nnrg958pkh6qhk0977u8c83jog6t[.]oast[.]fun | |
| MD5 | 1b20e9310ca815f9e2bd366fb94e147f | |
| MD5 | dd975310201079cacd4cde6facab8c1d | |
| MD5 | 86b62ffd33597fd635e01b95f08bb996 | |
| MD5 | f7f81ae880a17975f60e1e0fe1a4048b | |
| MD5 | 53c5b7d124f13039eb62409e1ec2089d | |
| ipv4-addr | 104[.]168[.]133[.]228 | |
| ipv4-addr | 149[.]154[.]176[.]41 | |
| MD5 | 30f57e14596f1bcad7cc4284d1af4684 | |
| MD5 | 62a611f0f1a418876b11c9df3b56885b | |
| MD5 | cacc30e2a5b2683e19e45dc4f191cebc | |
| MD5 | c7d20ca6fe596009afaeb725fec8635f | |
| MD5 | c2becc553b96ba27d60265d07ec3bd6c | |
| MD5 | aa69300617faab4eb39b789ebfeb5abe | |
| MD5 | 698a752ec1ca43237cb1dc791700afde | |
| MD5 | a50660fb31df96b3328640fdfbeea755 | |
| ipv4-addr | 45[.]141[.]215[.]17 | |
| MD5 | 061e5946c9595e560d64d5a8c65be49e | view.php |
| SHA-1 | cb6be7d4e741864817bd965ea4652364cccc9045 | view.php |
| SHA-256 | dcd04c0ac081fff41021d08cd882bcf70b696aa7824361ef23849e26f395148b | view.php |
| SSDEEP | 3:hTEd8x+QWp0SRJkHAhen:FE2x+QWuHoe | view.php |
| MD5 | 4895e11d30aa070fe45243a4e8b0e9dd | brokerDebug |
| SHA-1 | 20fecae6d41cce7a1f74313a3aeb97f7fa26895f | brokerDebug |
| SHA-256 | e35cf026057a3729387b7ecfb213ae62a611f0f1a418876b11c9df3b56885bed | brokerDebug |
| ipv4-addr | 64[.]176[.]49[.]160 | |
| ipv4-addr | 185[.]40[.]4[.]38 | |
| MD5 | c894f55c8fa9d92e2dd2c78172cff745 | |
| MD5 | f82847bccb621e6822a3947bc9ce9621 | |
| MD5 | ae51c891d2e895b5ca919d14edd42c26 | |
| ipv4-addr | 155[.]138[.]215[.]144 | |
| ipv4-addr | 188[.]172[.]229[.]15 | |
| ipv4-addr | 185[.]220[.]69[.]83 | |
| ipv4-addr | 185[.]199[.]103[.]196 | |
| ipv4-addr | 89[.]187[.]178[.]179 | |
| ipv4-addr | 216[.]73[.]162[.]56 | |
| ipv4-addr | 136[.]144[.]17[.]133 | |
| ipv4-addr | 136[.]144[.]17[.]145 | |
| ipv4-addr | 82[.]197[.]182[.]161 | |
| ipv4-addr | 154[.]213[.]185[.]230 | |
| ipv4-addr | 208[.]105[.]190[.]170 | |
| ipv4-addr | 185[.]40[.]4[.]95 | |
| ipv4-addr | 142[.]11[.]217[.]3 | |
| ipv4-addr | 134[.]195[.]90[.]71 | |
| MD5 | d13f71e51b38ffef6b9dc8efbed27615 | |
| MD5 | d88bfac2b43509abdc70308bef75e2a6 | |
| SHA-1 | 0f024f8487a9b908a8e81db7f6b4d85b70bbc212 | |
| SHA-256 | 3d0def685838f95a056d4fb5267b17ec3cc1c7a75fae0e4526b305cb964a1b88 | |
| MD5 | 78cc672218949a9ec87407ad3bcb5db6 | |
| SHA-1 | 25b79b4984a567b501e71fb3c43530a9b65d1c6e | |
| SHA-256 | 7cc4ed7bfd2a6f56ee1427a951bac36ad4e4e23fb66002d2befd2305e2d01bf3 | |
| domain-name | txt[.]xj[.]hk | |
| domain-name | gggg[.]oyr2ohrm[.]eyes[.]sh | |
| domain-name | ggg[.]oyr2ohrm[.]eyes[.]sh | |
| domain-name | gg[.]oyr2ohrm[.]eyes[.]sh | |
| url | https://file[.]io/frdZ9L18R7Nx | |
| url | https://file[.]io/RBKuU8gicWt | |
| url | https://file[.]io/E50vtqmJP5aa | |
| ipv4-addr | 203[.]160[.]72[.]174 | |
| ipv4-addr | 67[.]217[.]228[.]83 | |
| ipv4-addr | 108[.]174[.]199[.]200 | |
| domain-name | cdn[.]private-api[.]us[.]kg | |
| url | https://pan[.]xj[.]hk/d/6401646e701f5f47518ecef48a308a36/redis | |
| url | https://file[.]io/1zqvMYY1dpkk | |
| ipv4-addr | 107[.]173[.]89[.]16 | |
| ipv4-addr | 38[.]207[.]159[.]76 | |
| ipv4-addr | 23[.]236[.]66[.]97 | |
| ipv4-addr | 216[.]131[.]75[.]53 | |
| ipv4-addr | 205[.]169[.]39[.]11 | |
| ipv4-addr | 154[.]64[.]226[.]166 | |
| ipv4-addr | 142[.]171[.]217[.]195 | |
| ipv4-addr | 156[.]234[.]193[.]18 | |
| ipv4-addr | 98[.]101[.]25[.]30 | |
| ipv4-addr | 206[.]189[.]156[.]69 | |
| ipv4-addr | 192[.]42[.]116[.]210 | |
| MD5 | 60d5648d35bacf5c7aa713b2a0d267d3 | rar.exe |
| SHA-1 | a62af4ac233d914a25e79ec0705e2a187ebd7567 | rar.exe |
| SHA-256 | 4b16ea1b1273f8746cf399c71bfc1f5bff7378b5414b4ea044c55e0ee08c89d3 | rar.exe |
| SSDEEP | 12288:uPOMr1m/l86iW/YdYMl1trfDGbkg5eJmc1MziflRyHPTVL:uWMrE/a6iW/GYMljfDG4g5Xc+y7yHPTh | rar.exe |
| ipv4-addr | 203[.]160[.]86[.]69 | |
| domain-name | book[.]hacktricks[.]xyz | |
| domain-name | ip[.]sb |
Provenienza
Allegato ufficiale CISA · 2025-01-21T18:42:13Z
SHA-512: c7080932f97c1ce2846cb6dcc9f33c7a38ed4dce5b255837f77f81d361d95e55a5b7c4c4bc93a6d8c01ce0c707927ecfd85ba0ffceefa0f02559105edf5846ff
- Fonte
- CISA Cybersecurity Advisories
- Entità pubblicatrice
- CISA
- Tipo entità
- Autorità nazionale
- Area
- North America · US
- Lingua originale
- en · traduzione in preparazione
- Pubblicazione
- 31/01/2025 13:00
- Condivisione
- TLP:CLEAR
- MITRE ATT&CK
- T1059, T1068, T1071.001, T1140, T1190, T1210, T1219, T1505.003, T1548.003, T1552.001, T1556, T1564.002, T1595.002
- CVE
- CVE-2025-0282, CVE-2025-0283, CVE-2024-8963, CVE-2024-9379, CVE-2024-8190, CVE-2024-9380, CVE-2024-9381
- Classificazione
- Media
- Paese indicato
- US
Prodotti e versioni interessati
Il collector verificherà NVD e gli advisory vendor ufficiali disponibili.
Azione indicata dalla fonte
Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.
Riferimenti tecnici ufficiali
- https://www.cisa.gov/sites/default/files/2026-08/aa25-022a-threat-actors-chained-vulnerabilities-in-ivanti-cloud-service-applications_2.pdf
- https://www.cisa.gov/sites/default/files/2025-01/AA25-022A.stix__1.xml
- https://www.cisa.gov/sites/default/files/2025-01/AA25-022A-Threat-Actors-Chain-Vulnerabilities-In-Ivanti-Cloud-Service-Applications.stix__1.json