Urgent Alert: New DslogdRAT Malware Exploits Ivanti Zero-Day Vulnerability in Targeted Japan Attacks


# New Malware Targets Ivanti Connect Secure Vulnerability

Cybersecurity researchers have identified a new malware strain called DslogdRAT that exploits a recently patched vulnerability in Ivanti Connect Secure (ICS). According to JPCERT/CC researcher Yuma Masubuchi, the malware was deployed alongside a web shell by targeting CVE-2025-0282, a critical flaw that enables unauthenticated remote code execution.

The vulnerability, patched by Ivanti in January 2025, has been exploited as a zero-day by China-linked threat actor UNC5337 to deliver various malware including the SPAWN ecosystem, DRYHOOK, and PHASEJAM. Both JPCERT/CC and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) have documented attacks using this vulnerability to deploy updated SPAWN variants called SPAWNCHIMERA and RESURGE.

Google’s Mandiant also reported that another ICS vulnerability (CVE-2025-22457) has been weaponized by Chinese hacking group UNC5221 to distribute SPAWN malware. However, researchers have not yet confirmed whether the DslogdRAT attacks are connected to the SPAWN campaigns.

The attack sequence involves exploiting CVE-2025-0282 to deploy a Perl web shell, which then facilitates the installation of DslogdRAT. Once active, DslogdRAT establishes communication with an external server to transmit system information and receive commands for executing shell commands, transferring files, and using the compromised host as a proxy.

Threat intelligence firm GreyNoise has observed a nine-fold increase in suspicious scanning activity targeting ICS and Ivanti Pulse Secure appliances, with over 270 unique IP addresses detected in the past 24 hours and more than 1,000 in the last 90 days. Many of these originate from TOR exit nodes and suspicious hosting providers, primarily from the United States, Germany, and the Netherlands.

Share This Article