UTA0178__2024__Active_Exploitation_of_Two_Zero-Day_Vulnerabilities_in_Ivanti_Connect_Secure_VPN_Volexity.pdf
ID: 855a3ead-e8f2-4947-9b93-27ae3312fc3e
STIX ID: report--855a3ead-e8f2-4947-9b93-27ae3312fc3e
Threat Score
88/100
Uploaded: 2026-08-19
Published Date: 2024-01-12
Last Modified Date: 2024-01-12
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Volexity reports active exploitation of two zero-day vulnerabilities in Ivanti Connect Secure VPN devices, resulting in unauthenticated remote code execution, post-exploitation credential harvesting, webshell deployment, and lateral movement within affected networks. The investigation links the activity to threat actor alias UTA0178, potentially a Chinese nation-state group, and provides indicators of compromise and recommended detection and response steps for organizations deploying ICS VPN appliances.
