Stealth Cyber Attack Targets Ivanti EPMM: Dormant Backdoors Found Exploiting Critical Flaws

Listen to this Post

Featured Image
A new, stealthy cyber campaign has emerged, targeting Ivanti Endpoint Manager Mobile (EPMM) systems since February 4, 2026. Unlike conventional ransomware or data-stealing attacks, this operation is designed to stay hidden, silently establishing long-term access for future malicious activity. Exploiting two critical vulnerabilities—CVE-2026-1281 and CVE-2026-1340—attackers are planting dormant backdoors that remain under the radar, bypassing traditional security tools and evading detection.

Attack Summary: Patient and Silent Implants

The attackers have avoided immediate disruption, instead deploying malware to the web path /mifs/403.jsp. The implant is a Java class named base.Info from Info.java, which does not execute immediately. Rather than storing itself on disk, it lives in server memory, making it invisible to standard antivirus programs that scan only files.

Defused Cyber describes this as a “stage loader”—a harmless piece on its own, waiting for a precise HTTP request with the key k0f53cf964d387 to activate. When triggered, it decodes and executes a hidden payload. Clever coding tactics, such as using the equals(Object) method as an entry point, allow it to bypass security logs entirely.

Before fully activating, the malware fingerprints the system, checking operating system details and user information to ensure the target is valuable. Security researchers suspect involvement of Initial Access Brokers (IABs), who specialize in breaking into networks to sell access to other cybercriminals.

The malware’s SHA-256 hash is 097b051c9c9138ada0d2a9fb4dfe463d358299d4bd0e81a1db2f69f32578747a. Administrators should monitor for requests to /mifs/403.jsp and Base64 strings starting with yv66vg, which are indicators of the Java “magic bytes.”

Recommended Immediate Actions

Scan Logs: Check for hits on /mifs/403.jsp and suspicious Base64 payloads.

Restart Servers: Memory-resident malware disappears only on reboot; patching alone is insufficient.

Apply Updates: Install Ivanti’s patches for CVE-2026-1281 and CVE-2026-1340 to prevent new infections.

This campaign highlights the danger of quiet, persistent threats. Instead of immediate data theft, attackers maintain a covert presence, potentially selling network access to larger criminal operations.

Indicators of Compromise

Class Name: base.Info

Source File: Info.java

SHA-256: 097b051c9c9138ada0d2a9fb4dfe463d358299d4bd0e81a1db2f69f32578747a

Source IPs Involved

IP Address Organization ASN Country

104.219.171.96 Datacamp Limited AS212238 –

108.64.229.100 AT&T Enterprises, LLC AS7018 –

115.167.65.16 NTT America, Inc. AS2914 –

138.36.92.162 HOSTINGFOREX S.A. AS265645 –

146.103.53.35 Datacamp Limited AS212238 –

148.135.183.63 Datacamp Limited AS212238 –

151.247.221.59 Datacamp Limited AS212238 –

166.0.83.171 UK Dedicated Servers Ltd AS42831 –

172.59.92.152 T-Mobile USA, Inc. AS21928 –

185.240.120.91 Datacamp Limited AS212238 –

185.239.140.40 Datacamp Limited AS212238 –

194.35.226.128 LeaseWeb Netherlands B.V. AS60781 –

193.41.68.58 LeaseWeb Netherlands B.V. AS60781 –

77.78.79.243 SPCom s.r.o. AS204383 –

62.84.168.208 Hydra Communications Ltd AS25369 –

45.66.95.235 Hydra Communications Ltd AS25369 –

46.34.44.66 Liberty Global Europe AS6830 –

What Undercode Say:

This Ivanti EPMM attack demonstrates a shift in cybercriminal tactics toward patient, stealth-oriented campaigns rather than immediate disruption. Memory-resident malware like this stage loader is particularly dangerous because it avoids detection by file-based antivirus scanners. Organizations may believe they are safe simply because their antivirus reports are clean, but in reality, these implants persist silently, ready to deploy further payloads on command.

The use of Initial Access Brokers highlights a growing underground market where attackers specialize in gaining entry and selling access. Once this network foothold exists, larger ransomware or espionage operations can leverage it. The strategic placement in /mifs/403.jsp and the fingerprinting mechanism shows careful target selection, ensuring attackers maximize potential gains.

Operationally, patching alone isn’t enough. The malware’s memory-resident nature necessitates server restarts, along with immediate scanning for anomalous HTTP requests or Base64-encoded payloads. Administrators must also strengthen network monitoring, focusing on unusual system calls or Java-specific anomalies that traditional monitoring often misses.

From an intelligence perspective, multiple IPs from hosting providers and telecoms indicate a multi-stage operation, possibly using compromised or rented infrastructure to hide command-and-control traffic. The SHA-256 fingerprint provides a reliable detection mechanism, but reliance on a single indicator is risky; behavioral analysis and anomaly detection must complement it.

This incident reinforces the broader cybersecurity trend: attackers are increasingly favoring persistence and stealth over immediate financial gain. Systems exposed to known vulnerabilities like CVE-2026-1281 and CVE-2026-1340 remain prime targets for such campaigns, emphasizing the need for proactive vulnerability management and real-time network threat detection.

Organizations should prioritize memory-level monitoring, integrate threat intelligence feeds for emerging IAB activity, and enforce strict server reboot protocols post-patch. Waiting until a visible breach occurs could result in network access being sold to high-value cybercriminal buyers, escalating potential losses.

Fact Checker Results

✅ The malware targets Ivanti EPMM via CVE-2026-1281 and CVE-2026-1340.
✅ It operates in memory, evading traditional file-based antivirus detection.
❌ There is no evidence of immediate ransomware or data exfiltration; it is primarily a stealth persistence threat.

Prediction

🔮 This type of attack is likely to become more common, with memory-resident implants increasingly used to establish long-term network access. Companies using Ivanti EPMM or similar endpoint management tools should expect more sophisticated IAB-driven campaigns in the coming months. Early detection and system hardening will be critical to prevent larger-scale breaches.

If you want, I can also make a visual flowchart showing how this malware stage loader activates to make the technical part easier to grasp. Do you want me to do that?

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://stackoverflow.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon