Single Actor Dominates Ivanti Exploits
Executive Summary
A single threat actor, operating from bulletproof hosting, is reportedly responsible for 83% of exploitation attempts against critical remote code execution (RCE) vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM).
The campaign focuses on compromising unpatched servers to gain initial access for potential follow-on attacks.
Key TTPs
- Initial Access: Exploiting unauthenticated code injection vulnerabilities in public-facing EPMM appliances.
- Execution: Chaining vulnerabilities to achieve remote code execution and deploy web shells for persistent access.
Campaign Analysis
The high concentration of attacks from one source suggests a well-resourced, automated campaign to identify vulnerable systems at scale.
This activity is consistent with an initial access broker cataloging compromised devices for future sale or exploitation.
Targeting & Infrastructure
- Target Profile: European government and judicial agencies (e.g., European Commission, Dutch AP), and decentralized infrastructure (I2P network) currently under Sybil attack by the Kimwolf botnet.
- Infrastructure: The majority of attacks originate from a single IP address (
193[.]24[.]123[.]42) hosted on bulletproof infrastructure.
Relevant Terms
- Remote Code Execution (RCE): A vulnerability that allows an attacker to execute arbitrary commands on a target system over a network.
- Bulletproof Hosting: A service provided by a web hosting company that is resilient to takedown requests, often used for malicious activities.
Source: BleepingComputer
