CISA has identified a sophisticated new malware called RESURGE targeting Ivanti Connect Secure appliances through the CVE-2025-0282 vulnerability. This malware builds upon capabilities found in the SPAWNCHIMERA variant while introducing distinctive new features.
## Malware Capabilities
RESURGE functions as a multi-purpose threat combining rootkit, dropper, backdoor, bootkit, proxy, and tunneler capabilities. Its enhanced functionality includes:
– Inserting itself into “ld.so.preload”
– Establishing web shells for credential harvesting
– Creating unauthorized accounts
– Resetting passwords and escalating privileges
– Copying malicious code to the boot disk
– Manipulating the coreboot image
## Affected Systems
The vulnerability impacts:
– Ivanti Connect Secure (versions before 22.7R2.5)
– Ivanti Policy Secure (versions before 22.7R1.2)
– Ivanti Neurons for ZTA gateways (versions before 22.7R2.3)
## Threat Actors
Security researchers attribute this activity to Chinese threat actors:
– UNC5337 has been linked to the SPAWN malware ecosystem
– Silk Typhoon (formerly Hafnium) has also exploited this vulnerability
## Additional Components
CISA discovered two other components on compromised systems:
– A SPAWNSLOTH variant that tampers with device logs
– A custom Linux binary containing BusyBox applets capable of extracting uncompressed kernel images
## Recommended Mitigations
Organizations should:
– Update Ivanti instances to the latest version
– Reset credentials for all privileged and non-privileged accounts
– Rotate passwords for domain and local users
– Review and temporarily revoke access privileges for affected devices
– Monitor accounts for suspicious activity
The ongoing refinement of these attack tools highlights the need for immediate remediation actions.
