logo

UTA0178__2024__Active_Exploitation_of_Two_Zero-Day_Vulnerabilities_in_Ivanti_Connect_Secure_VPN_Volexity.pdf

ID: 855a3ead-e8f2-4947-9b93-27ae3312fc3e

STIX ID: report--855a3ead-e8f2-4947-9b93-27ae3312fc3e

Threat Score

88/100

Uploaded: 2026-08-19

Published Date: 2024-01-12

Last Modified Date: 2024-01-12

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Volexity reports active exploitation of two zero-day vulnerabilities in Ivanti Connect Secure VPN devices, resulting in unauthenticated remote code execution, post-exploitation credential harvesting, webshell deployment, and lateral movement within affected networks. The investigation links the activity to threat actor alias UTA0178, potentially a Chinese nation-state group, and provides indicators of compromise and recommended detection and response steps for organizations deploying ICS VPN appliances.