Malware Mayhem: New DslogdRAT Exploits Past Security Flaw in Ivanti Connect Secure
Cybersecurity researchers have discovered DslogdRAT, a sneaky malware exploiting now-patched Ivanti Connect Secure flaws. It’s like a digital ninja—installed via a zero-day exploit, it stealthily awaits orders to execute commands, upload files, and turn your computer into a proxy. Watch out, it’s more than just a rat in the cyber maze!

Hot Take:
Looks like cyber villains are treating vulnerabilities like fine wines – the older they get, the more valuable they become. With the DslogdRAT malware making its grand entrance, it’s clear that hackers are scripting their own version of the soap opera: “As the Exploit Turns.” Who knew cybersecurity could have such dramatic plot twists?
Key Points:
- DslogdRAT malware is exploiting a previously patched flaw in Ivanti Connect Secure.
- The flaw, CVE-2025-0282, was initially exploited by a China-linked group, UNC5337.
- New versions of SPAWN malware, SPAWNCHIMERA, and RESURGE, are being distributed using the same flaw.
- Another Chinese group, UNC5221, is using a different ICS security flaw to spread SPAWN.
- GreyNoise reports a significant increase in suspicious activity targeting ICS and IPS appliances.
Already a member? Log in here