CISA Alerts on RESURGE Malware Exploiting Ivanti Connect Secure Zero-Days
The Cybersecurity and Infrastructure Security Agency (CISA) has published a Malware Analysis Report (MAR) detailing a new malware strain, RESURGE, exploiting a zero-day vulnerability in Ivanti Connect Secure devices.
The Cybersecurity and Infrastructure Security Agency (CISA) has published a Malware Analysis Report (MAR) detailing a new malware strain, RESURGE, exploiting a zero-day vulnerability in Ivanti Connect Secure devices.
RESURGE advances the functionality of the prior SPAWNCHIMERA malware, introducing new commands to enhance persistence and expand capabilities in credential theft and privilege escalation. It performs distinctive operations affecting system integrity checks and core security processes.
Deploying web shells within Ivanti systems Manipulating integrity checks to avoid detection Modifying critical files during system operation Facilitating credential harvesting, account creation, password resets, and privilege escalation
The malware additionally copies web shells to the Ivanti device’s boot disk and alters the coreboot image, ensuring persistence even post-reboot or partial restoration.
Link to Ivanti CVE-2025-0282 Exploitation
CISA associates these intrusions with the exploitation of CVE-2025-0282, a stack-based buffer overflow vulnerability in Ivanti products, allowing remote attackers to execute arbitrary code and maintain persistent access.
It performs distinctive operations affecting system integrity checks and core security processes.
The MAR, identified as MAR-25993211.R1.V1.CLEAR, includes technical details, YARA detection rules, and SIGMA signatures for identifying the malware, available on the CISA portal for rapid implementation by security teams.
CISA recommends organizations take immediate action, emphasizing that patching alone may not remove the malware. Recommended steps include:
Performing a full factory reset of affected appliances Using a known clean external image to reset cloud or virtual systems Following Ivanti’s Recommended Recovery Steps
Resetting credentials for all accounts Enforcing password resets for domain and local accounts, particularly for the krbtgt account, resetting twice with replication Reviewing and adjusting account privileges on affected systems
To avoid alerting attackers during threat intelligence collection, CISA suggests temporarily reducing privileges instead of immediate resets. Administrators should monitor privileged accounts for any unauthorized access attempts.
The full CISA malware report MAR-25993211.R1.V1.CLEAR and associated SIGMA rules are available for updated detection. CISA highlights that complete remediation and credential resets are necessary to prevent attackers from regaining access.
Based on reporting by GBHackers.
