Technology NewsTechnology NewsTechnology News
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Reading: New Variant of WIREFIRE Web Shell Targets Ivanti VPN Appliances
Share
Font ResizerAa
Technology NewsTechnology News
Font ResizerAa
Search
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Follow US
  • Cookie Policy (EU)
  • Contact
  • About
© 2025 NEWSLINKER - Powered by LK SOFTWARE
Cybersecurity

New Variant of WIREFIRE Web Shell Targets Ivanti VPN Appliances

Highlights

  • QuoIntelligence reveals a new WIREFIRE variant.

  • Variant evades detection, retains core functions.

  • New YARA rule developed for broader detection.

NEWSLINKER
Last updated: 24 January, 2024 - 5:29 pm 5:29 pm
NEWSLINKER 1 year ago
Share
SHARE

A recent investigation by QuoIntelligence has led to the discovery of a sophisticated new variant of the WIREFIRE web shell, specifically targeting Ivanti Connect Secure VPN appliances. This development reveals the lengths to which cyber adversaries will go to avoid detection and maintain their foothold within compromised systems.

Contents
Uncovering a Stealthy Cyber ThreatAnalyzing the Enhanced Web ShellProactive Measures and New Detection Tools

Uncovering a Stealthy Cyber Threat

In December 2023, the cybersecurity community became aware of a widespread campaign exploiting vulnerabilities in Ivanti VPN appliances. The attackers, identified as the UNC5221 group, utilized web shells to gain unauthorized access to both internal and external web applications.

QuoIntelligence’s team found a new version of the WIREFIRE web shell that had gone unreported. This variant was cleverly hidden within a different file, allowing it to escape existing security measures designed to detect the original version.

Analyzing the Enhanced Web Shell

The new variant shared the primary features of its predecessor, intercepting and executing encrypted data payloads in memory to avoid leaving traces. However, it introduced two significant changes: the use of cookies for payload delivery and the persistent execution of malicious code through the “exec()” function.

These alterations rendered Mandiant’s YARA rule, which was meant to detect the WIREFIRE web shell, ineffective. This exemplifies the attackers’ strategy of deploying modified versions to circumvent detection based on specific file paths.

Proactive Measures and New Detection Tools

In response to this challenge, QuoIntelligence developed a new YARA rule with a broader scope, capable of detecting both the original web shell and its variant. Organizations are advised to implement this rule, keep systems updated, and maintain awareness of evolving threats.

You can follow us on Youtube, Telegram, Facebook, Linkedin, Twitter ( X ), Mastodon and Bluesky

You Might Also Like

Cyberattack Forces PowerSchool to Face Extortion Scandal

CrowdStrike Faces Workforce Reduction Amid Financial Shifts

Authorities Seize DDoS Platforms in Multi-National Operation

Trump Urges Colorado to Release Jailed Clerk Over Election Breach

Google Targets Vulnerabilities in May Security Update

Share This Article
Facebook Twitter Copy Link Print
By NEWSLINKER
NEWS LINKER is your premier source for the latest in business, finance, science, gaming, and technology. We are dedicated to bringing you the most accurate, timely, and engaging content from across these dynamic industries. Dive deep into the world of cutting-edge developments, breakthroughs, market trends, and game-changing innovations..
Previous Article Ironwood Studios Unveils Unique Rogue-lite Game ‘Pacific Drive’
Next Article Leaked Packaging Hints at Google Pixel 8a’s Sleeker Design and Enhanced Features

Stay Connected

6.2kLike
8kFollow
2.3kSubscribe
1.7kFollow

Latest News

Trump Alters AI Chip Export Strategy, Reversing Biden Controls
AI
Solve Wordle’s Daily Puzzle with These Expert Tips
Gaming
US Automakers Boost Robot Deployment in 2024
Robotics
Uber Expands Autonomy Partnership with $100 Million Investment in WeRide
Robotics
EB Games Returns to Canada and Recaptures Nostalgia
Gaming
NEWSLINKER – your premier source for the latest updates in ai, robotics, electric vehicle, gaming, and technology. We are dedicated to bringing you the most accurate, timely, and engaging content from across these dynamic industries. Join us on our journey of discovery and stay informed in this ever-evolving digital age.

ARTIFICAL INTELLIGENCE

  • Can Artificial Intelligence Achieve Consciousness?
  • What is Artificial Intelligence (AI)?
  • How does Artificial Intelligence Work?
  • Will AI Take Over the World?
  • What Is OpenAI?
  • What is Artifical General Intelligence?

ELECTRIC VEHICLE

  • What is Electric Vehicle in Simple Words?
  • How do Electric Cars Work?
  • What is the Advantage and Disadvantage of Electric Cars?
  • Is Electric Car the Future?

RESEARCH

  • Robotics Market Research & Report
  • Everything you need to know about IoT
  • What Is Wearable Technology?
  • What is FANUC Robotics?
  • What is Anthropic AI?
Technology NewsTechnology News
Follow US
About Us   -  Cookie Policy   -   Contact

© 2025 NEWSLINKER. Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Register Lost your password?