Threat Brief: CVE-2025-0282 and CVE-2025-0283

Jan. 17, 2025, 5:54 p.m.

Description

Two critical vulnerabilities in Ivanti Connect Secure, Policy Secure and ZTA gateway products have been discovered. CVE-2025-0282 allows remote code execution, while CVE-2025-0283 enables privilege escalation. Attacks exploiting CVE-2025-0282 have been observed in the wild, involving initial access, credential harvesting, lateral movement, defense evasion, and persistence. Attackers used custom tools like SPAWNMOLE, SPAWNSNAIL, and SPAWNSLOTH. The activity cluster CL-UNK-0979 has been identified, potentially linked to UNC5337. Immediate patching and monitoring are strongly recommended. Various Palo Alto Networks products offer protection against these threats.

Date

  • Created: Jan. 17, 2025, 5:17 p.m.
  • Published: Jan. 17, 2025, 5:17 p.m.
  • Modified: Jan. 17, 2025, 5:54 p.m.

Indicators

  • a6b24fcef2e018c9ef634aa21e26a74ff94ea508a8b132fad38d48f5ab10fcd3
  • 75a3d53c1d63ecb338d4b2d6f5b3d980b0caceb77808ed81ab73b49138cc0a26
  • 723711ccbb3eaf1daea3d5b00aa6aaee48a359be395d9500d8a56609ec5238e9
  • f9ca95119b32a18491e3cc28c7020ee00f6e7a45ae089c876d87252e754e5a2e
  • 1dc0a3a5904ec35103538a018ef069fbe95b0a3c26cb0ff9ba0d1c268d1aaf98
  • 43363aa0d1fdab0174d94bd5a9e16d47cbb08b4b089c5a12e370133ab8e640a6
  • 3526af9189533470bc0e90d54bafb0db7bda784be82a372ce112e361f7c7b104
  • 366635c00b8e6f749a4d948574a0f1e7b4c842ca443176de27af45debbc14f71
  • aae291ac5767cfe93676dacb67ba50c98d8fd520f5821fb050fd63e38b000b18
  • 7144b8c77d261985205ae2621eb6242f43d6244e18b8d01d05048337346b6efd
  • 168.100.8.144
  • 193.149.180.128
  • 185.219.141.95
  • 185.195.71.244

Attack Patterns

  • SPAWNSLOTH
  • SPAWNSNAIL
  • SPAWNMOLE
  • UNC5337
  • T1505.003
  • T1543.003
  • T1053.005
  • T1055.012
  • T1571
  • T1190
  • T1003
  • T1059