Exposed: RESURGE Malware Weaponizes Ivanti Vulnerability with Advanced Rootkit and Backdoor Capabilities


# RESURGE Malware Targets Ivanti Connect Secure Vulnerabilities

CISA has identified a sophisticated new malware called RESURGE targeting Ivanti Connect Secure appliances through the CVE-2025-0282 vulnerability. This malware builds upon capabilities found in the SPAWNCHIMERA variant while introducing distinctive new features.

## Malware Capabilities

RESURGE functions as a multi-purpose threat combining rootkit, dropper, backdoor, bootkit, proxy, and tunneler capabilities. Its enhanced functionality includes:

– Inserting itself into “ld.so.preload”
– Establishing web shells for credential harvesting
– Creating unauthorized accounts
– Resetting passwords and escalating privileges
– Copying malicious code to the boot disk
– Manipulating the coreboot image

## Affected Systems

The vulnerability impacts:
– Ivanti Connect Secure (versions before 22.7R2.5)
– Ivanti Policy Secure (versions before 22.7R1.2)
– Ivanti Neurons for ZTA gateways (versions before 22.7R2.3)

## Threat Actors

Security researchers attribute this activity to Chinese threat actors:
– UNC5337 has been linked to the SPAWN malware ecosystem
– Silk Typhoon (formerly Hafnium) has also exploited this vulnerability

## Additional Components

CISA discovered two other components on compromised systems:
– A SPAWNSLOTH variant that tampers with device logs
– A custom Linux binary containing BusyBox applets capable of extracting uncompressed kernel images

## Recommended Mitigations

Organizations should:
– Update Ivanti instances to the latest version
– Reset credentials for all privileged and non-privileged accounts
– Rotate passwords for domain and local users
– Review and temporarily revoke access privileges for affected devices
– Monitor accounts for suspicious activity

The ongoing refinement of these attack tools highlights the need for immediate remediation actions.

Share This Article