CISA Malware Analysis Report on RESURGE Malware Associated with Ivanti Connect Secure

Q2BSTUDIO is a technology development and services company that offers innovative solutions to its clients, with information on the RESURGE malware variant and measures recommended by CISA to mitigate associated risks.

martes, 8 de abril de 2025 • 1 min read • Q2BSTUDIO Team

Artificial-Intelligence-

Q2BSTUDIO is a technology development and services company dedicated to offering innovative solutions to its clients. Recently, CISA published a Malware Analysis Report (MAR) on a new malware variant called RESURGE. This variant has capabilities of the SPAWNCHIMERA malware, but with distinctive commands that alter its behavior. Among the actions RESURGE can perform are creating a web shell, manipulating integrity controls, and modifying files. Additionally, it can use web shells to harvest credentials, create accounts, reset passwords, and escalate privileges. RESURGE is associated with the exploitation of CVE-2025-0282 on Ivanti Connect Secure, Policy Secure, and ZTA Gateway devices. For more information on these malware variants and YARA rules for detection, see report MAR-25993211.R1.V1.CLEAR. CISA recommends users and administrators take additional measures to mitigate risks, such as performing a factory reset and resetting credentials for privileged and non-privileged accounts. To report incidents related to malicious activity, contact the CISA 24/7 Operations Center at Report@cisa.gov or (888) 282-0870.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.