Q2BSTUDIO is a technology development and services company dedicated to offering innovative solutions to its clients. Recently, CISA published a Malware Analysis Report (MAR) on a new malware variant called RESURGE. This variant has capabilities of the SPAWNCHIMERA malware, but with distinctive commands that alter its behavior. Among the actions RESURGE can perform are creating a web shell, manipulating integrity controls, and modifying files. Additionally, it can use web shells to harvest credentials, create accounts, reset passwords, and escalate privileges. RESURGE is associated with the exploitation of CVE-2025-0282 on Ivanti Connect Secure, Policy Secure, and ZTA Gateway devices. For more information on these malware variants and YARA rules for detection, see report MAR-25993211.R1.V1.CLEAR. CISA recommends users and administrators take additional measures to mitigate risks, such as performing a factory reset and resetting credentials for privileged and non-privileged accounts. To report incidents related to malicious activity, contact the CISA 24/7 Operations Center at Report@cisa.gov or (888) 282-0870.




