Target Industry
Indiscriminate, opportunistic targeting.
Overview
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a new malware variant called RESURGE. The malware exploits a critical vulnerability, CVE-2025-0282, in Ivanti Connect Secure devices.
Impact
The RESURGE malware allows threat actors to gain unauthorised access and control over affected systems. The threat actors establish secure tunnels for command-and-control (C2) operations, which potentially may result in data exfiltration. The malware compromises system integrity by disrupting normal operations by modifying system files and installing a web shell. RESURGE also incorporates encryption mechanisms to evade detection, making it difficult for security teams to identify and remove the threat.
Affected Products
- Ivanti Connect Secure before version 22.7R2.5
- Ivanti Policy Secure before version 22.7R1.2
- Ivanti Neurons for ZTA gateways before version 22.7R2.3
Exploitation
The RESURGE malware exploits the Ivanti Connect Secure vulnerability, CVE-2025-0282 (CVSS score of 9.0, critical). Threat actors gain initial access by bypassing any authentication mechanisms in place. RESURGE installs a backdoor, enabling Secure Shell (SSH) tunnels to be established for C2 operations. The malware modifies critical system files, bypasses integrity checks, and installs a web shell on the Ivanti boot disk. RESURGE also uses encryption mechanisms to evade detection, making it difficult for security teams to identify and remove the threat. Additionally, a related variant, SPAWNSLOTH, tampers with system logs, complicating efforts to trace and investigate malicious activities.
Containment, Mitigations & Remediations
CISA has recommended the following steps to mitigate RESURE malware:
- Patch Ivanti appliances: Update Ivanti devices to the latest firmware version to fix vulnerabilities
- Reset credentials: Change all passwords for both privileged and non-privileged accounts
- Rotate passwords: Regularly change passwords for all domain and local accounts to enhance security
- Review and revoke access: Check and remove unnecessary access privileges on affected devices
- Monitor activity: Check network and account access logs for any unusual or suspicious activity.
Threat Landscape
The RESURGE malware exploiting the Ivanti Connect Secure vulnerability is quite concerning as it employs advanced techniques. There is the potential that it can lead to data exfiltration, causing organisations to have significant data breaches. This underscores the need for proactive and comprehensive cyber security measures to protect against such sophisticated threats.
Threat Groups
The RESURGE malware is believed to be linked to cyber espionage groups associated with China due to CVE-2025-0282 being exploited. This has recently been exploited by three believed to be Chinese threat actor groups, UNC5337, Silk Typhoon (formerly Hafnium) and UNC5221.
Further Information













