Listen to this Post

In December 2024, Japanese organizations became the victims of a sophisticated cyberattack utilizing a zero-day vulnerability. The exploit targeted Ivanti software, allowing attackers to deploy a new malware called DslogdRAT. JPCERT/CC researchers have outlined the details of the attack, which highlights the growing threat from such vulnerabilities and the persistence of cybercriminal groups in targeting critical infrastructure.
The vulnerability in question is tracked as CVE-2025-0282, with a severity score of 9.0 (CVSS). This stack-based buffer overflow affects several Ivanti products, including Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA gateways. The flaw allows unauthenticated attackers to execute arbitrary code remotely, while local authenticated users can escalate their privileges.
In response to this growing threat, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog in January 2025. In March 2025, Microsoft reported that APT group Silk Typhoon, believed to be a China-backed threat actor linked to the US Treasury hack, had exploited the zero-day in attacks targeting global IT supply chains. The attack strategy involved compromising IT firms to spy on networks and move laterally within organizations.
JPCERT/CC’s findings reveal that the attackers leveraged a Perl-based CGI web shell to exploit this vulnerability. The web shell was designed to check for a specific DSAUTOKEN cookie value in HTTP requests. When matched, the attackers could execute arbitrary commands on the affected systems, possibly deploying the DslogdRAT malware. This tactic allowed them to move deeper into compromised networks.
DslogdRAT functions by spawning two child processes upon execution. The first process remains idle in a loop, while the second handles crucial functions such as communication with the command-and-control (C2) server and executing commands. The malware’s configuration is encoded using XOR encryption, and it operates only between 8 AM and 8 PM to evade detection by blending in with normal business activity.
The malware also supports proxy functionality, file uploads and downloads, and executing shell commands remotely, all while communicating with the C2 server using simple XOR encoding. The attack also involved another malware, SPAWNSNARE, which was found in the same system. SPAWNSNARE was previously reported by CISA and Google in April 2025.
What Undercode Says: Analyzing the Attack and Its Implications
The cyberattack leveraging the CVE-2025-0282 vulnerability serves as a critical reminder of the growing sophistication and persistence of cybercriminal groups targeting global organizations. This specific attack not only highlights the severity of zero-day vulnerabilities but also the advanced tactics employed by threat actors, such as the use of a web shell to deploy malicious payloads.
The use of a Perl-based CGI web shell is an interesting tactic that demonstrates the flexibility and creativity of attackers in using seemingly innocuous methods to infiltrate networks. The check for a specific cookie value to trigger command execution shows how attackers are taking advantage of weak or misconfigured security measures to gain access to sensitive systems.
The deployment of DslogdRAT malware through this exploit demonstrates the increasing complexity of modern malware. By spawning two child processes, one of which remains idle to avoid detection, the malware mimics legitimate system behavior and evades traditional detection methods. This technique is a form of behavioral obfuscation, making it more difficult for security teams to identify the presence of the malware.
Furthermore, the malware’s use of simple XOR encoding for C2 communications and its set operating hours—matching typical business hours—reflects a strategic approach to blend in with normal network traffic. By operating within predictable patterns, attackers can avoid triggering security systems that rely on anomaly detection.
The involvement of another piece of malware, SPAWNSNARE, in the same attack further highlights the complexity of the cyber threat landscape. Attackers are increasingly using multiple tools in tandem, each serving a different purpose within the broader attack strategy. The combination of these tools allows attackers to maintain access, exfiltrate data, and move laterally within compromised networks.
This attack also underscores the importance of patch management. Organizations relying on outdated versions of Ivanti software were at significant risk, as the vulnerability was actively exploited by attackers. The fact that CVE-2025-0282 was added to CISA’s KEV catalog should serve as a wake-up call for organizations to prioritize vulnerability remediation and stay on top of critical updates.
Another key point to note is the involvement of a state-backed APT group, Silk Typhoon. The attack targeted global IT supply chains, using IT firms to infiltrate various networks and expand their reach. This points to a broader geopolitical strategy of espionage and cyber warfare, where nation-state actors are increasingly using cyber capabilities to advance their interests on the global stage.
Given the sophistication of this attack, it is clear that organizations must adopt a multi-layered security approach that includes proactive threat hunting, real-time monitoring, and timely patching of known vulnerabilities. The threat of zero-day exploits and advanced persistent threats requires organizations to rethink their security strategies and invest in robust defense mechanisms.
Fact Checker Results
- CVE-2025-0282 is a zero-day vulnerability with a CVSS score of 9.0, affecting Ivanti software products, including Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA.
- DslogdRAT uses a unique tactic by operating during business hours to evade detection and communicates via XOR-encoded C2 channels.
- SPAWNSNARE, another malware discovered in the same attack, was also reported by CISA and Google in 2025.
References:
Reported By: securityaffairs.com
Extra Source Hub:
https://www.facebook.com
Wikipedia
Undercode AI
Image Source:
Unsplash
Undercode AI DI v2




