RESURGE Malware Targeting Ivanti Connect Secure

The Cybersecurity and Infrastructure Security Agency (CISA) has released a Malware Analysis Report (MAR) detailing a newly discovered malware variant, RESURGE, linked to CVE-2025-0282, a critical vulnerability in Ivanti Connect Secure, Policy Secure, and ZTA Gateways.

Key Findings on RESURGE Malware

RESURGE builds on the capabilities of SPAWNCHIMERA malware but introduces new commands that:

  • Create and manipulate web shells for credential harvesting and privilege escalation.
  • Modify system files and integrity checks to maintain persistence.
  • Survive reboots by embedding itself in the Ivanti running boot disk.

CVE-2025-0282, a stack-based buffer overflow flaw, was added to CISA’s Known Exploited Vulnerabilities Catalog in January 2025, signaling active exploitation in the wild.

Mitigation Recommendations

CISA urges organizations to take immediate action, including:

  1. Perform a factory reset using a clean external image for virtual/cloud systems.
  2. Reset all privileged and non-privileged account credentials, including domain users.
  3. Review and restrict access policies to limit exposure.
  4. Monitor administrative accounts for unauthorized activity.

References

https://www.cisa.gov/news-events/alerts/2025/03/28/cisa-releases-malware-analysis-report-resurge-malware-associated-ivanti-connect-secure

You may also like these