Malware Mayhem: New DslogdRAT Exploits Past Security Flaw in Ivanti Connect Secure

Cybersecurity researchers have discovered DslogdRAT, a sneaky malware exploiting now-patched Ivanti Connect Secure flaws. It’s like a digital ninja—installed via a zero-day exploit, it stealthily awaits orders to execute commands, upload files, and turn your computer into a proxy. Watch out, it’s more than just a rat in the cyber maze!

Pro Dashboard

Hot Take:

Looks like cyber villains are treating vulnerabilities like fine wines – the older they get, the more valuable they become. With the DslogdRAT malware making its grand entrance, it’s clear that hackers are scripting their own version of the soap opera: “As the Exploit Turns.” Who knew cybersecurity could have such dramatic plot twists?

Key Points:

  • DslogdRAT malware is exploiting a previously patched flaw in Ivanti Connect Secure.
  • The flaw, CVE-2025-0282, was initially exploited by a China-linked group, UNC5337.
  • New versions of SPAWN malware, SPAWNCHIMERA, and RESURGE, are being distributed using the same flaw.
  • Another Chinese group, UNC5221, is using a different ICS security flaw to spread SPAWN.
  • GreyNoise reports a significant increase in suspicious activity targeting ICS and IPS appliances.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?