Target Industry

Indiscriminate, opportunistic targeting.

Overview

The largest UK domain registry, Nominet, has experienced a breach to its system due to a zero-day vulnerability in Ivanti. The breach exploited the Ivanti VPN Connect Secure vulnerability, CVE-2025-0282, which has a CVSS base score of 9.0, allowing unauthenticated remote code execution (RCE) on their systems. A patch for the vulnerability was released on 8th January . Nominet has stated that there is no evidence of a data breach and is still investigating the issue. The potential data leakage could include billing information as well as technical contacts. This could lead to an increase in targeted social engineering attacks using the potentially breached data.

Technical Overview

The breach was caused by a zero-day vulnerability in the Ivanti product identified as CVE-2025-0282. The attacker initially gained access through a stack-based buffer overflow on Ivanti VPN Connect Secure that allowed RCE. While information is limited from Nominet, the cyber security company working with Ivanti has commented on the general processes attackers have taken with their affected customers. The threat actor uses their own Spawn Malware Toolkit to create “PhaseJam” and “DryHook”, their own custom malware, to retrieve data and modify the system. PhaseJam deploys a web shell to compromised components such as “getComponent.cgi” and “restAuth.cgi”. DryHook captures the username and password during standard authentication processes and stores them in base64 for future retrieval. They also modified the “DSUpgrade.pm” to stop the computer from upgrading and removing the malware by showing a fake update as well as having measures on the toolkit to avoid detection, such as changing its own hash. Other malware of the SPAWN ecosystem was also used. Another Ivanti product, Ivanti Policy Secure, was also affected by this vulnerability. More information on the CVE can be seen in our previous bulletin linked at the bottom.

Impact

While Nominet hasn’t found any evidence that data was stolen, there is still a chance that customer information has been leaked which will help threat actors attempt social engineering by appearing more legitimate as they may be holding technical contacts and billing details. A more severe impact would cause disruptions to the websites as well as redirecting to a malicious site.

Threat Group

Mandiant has attributed the exploitation campaign to the threat actor group tracked as UNC5337, a China-linked activity group suspected to be part of a larger cluster tracked as UNC5221. The latter has a history of exploiting Ivanti vulnerabilities such as CVE-2023-46805 and CVE-2024-21887, which impacted Ivanti Connect Secure VPN and Ivanti Policy Security appliances. In these campaigns, UNC5337 reportedly deployed several custom malware payloads including the SPAWNSNAIL passive backdoor, SPAWNMOLE tunneller, SPAWNANT installer, and SPAWNSLOTH log tampering utility. Quorum Cyber’s Threat Intelligence team has assessed that UNC5337 is likely seeking to exploit Ivanti products to gain initial access to target systems with the objectives of cyber espionage and intelligence collection on behalf of the Chinese state.

TTPs

Tactic

Techniques

Further Information

1. https://www.quorumcyber.com/threat-intelligence/ivanti-connect-secure-policy-secure-zta-gateways-vulnerabilities/ 2. Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation | Google Cloud Blog 3. https://nvd.nist.gov/vuln/detail/CVE-2025-0282 4. https://github.com/securexploit1/CVE-2025-0282 5. https://cloud.google.com/blog/topics/threat-intelligence/ivanti-connect-secure-vpn-zero-day

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content