Norwegian Entities Targeted in Ongoing Attacks Exploiting Ivanti EPMM Vulnerability

Teilen:

Advanced persistent threat (APT) actors exploited a recently disclosed critical flaw impacting Ivanti Endpoint Manager Mobile (EPMM) as a zero-day since at least April 2023 in attacks directed against Norwegian entities, including a government network.

The disclosure comes as part of a new joint advisory released by the Cybersecurity and Infrastructure Security Agency (CISA) and the Norwegian National Cyber Security Centre (NCSC-NO) Tuesday. The exact identity or origin of the threat actor remains unclear.

The APT actors have exploited CVE-2023-35078 since at least April 2023, the authorities said. The actors leveraged compromised small office/home office (SOHO) routers, including ASUS routers, to proxy to target infrastructure.’

CVE-2023-35078 refers to a severe flaw that allows threat actors to access personally identifiable information (PII) and gain the ability to make configuration changes on compromised systems. It can be chained with a second vulnerability, CVE-2023-35081, to cause unintended consequences on targeted devices.

Successful exploitation of the twin vulnerabilities makes it possible for adversaries with EPMM administrator privileges to write arbitrary files, such as web shells, with operating system privileges of the EPMM web application server.

The attackers have also been observed tunneling traffic from the internet through Ivanti Sentry, an application gateway appliance that supports EPMM, to at least one Exchange server that was not accessible from the internet, although it’s currently unknown how this was accomplished.

Further analysis has revealed the presence of a WAR file called mi.war on Ivanti Sentry, which has been described as a malicious Tomcat application that deletes log entries based on a specific string – Firefox/107.0 – contained in a text file.

The APT actors used Linux and Windows user agents with Firefox/107.0 to communicate with EPMM, the agencies said. Mobile device management (MDM) systems are attractive targets for threat actors because they provide elevated access to thousands of mobile devices.

A majority of the 5,500 EPMM servers on the internet are located in Germany, followed by the U.S., the U.K., France, Switzerland, the Netherlands, Hong Kong, Austria, China, and Sweden, according to Palo Alto Networks Unit 42.

To mitigate against the ongoing threat, it’s recommended that organizations apply the latest patches as soon as possible, mandate phishing-resistant multi-factor authentication (MFA) for all staff and services, and validate security controls to test their effectiveness.

 

(c) Thin

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
8:45 am, Mai 24, 2025
Wetter-Symbol 14°C
L: 14° | H: 15°
light rain
Luftfeuchtigkeit: 89 %
Druck: 1012 mb
Wind: 9 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0.11 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:56 am
Sonnenuntergang: 8:58 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
14° | 15°°C 0.24 mm 24% 14 mph 89 % 1012 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
13° | 19°°C 1 mm 100% 16 mph 92 % 1015 mb 0 mm/h
Mo. Mai 26 10:00 pm
Wetter-Symbol
10° | 16°°C 0.78 mm 78% 15 mph 78 % 1017 mb 0 mm/h
Di. Mai 27 10:00 pm
Wetter-Symbol
13° | 17°°C 1 mm 100% 15 mph 95 % 1016 mb 0 mm/h
Mi. Mai 28 10:00 pm
Wetter-Symbol
14° | 21°°C 1 mm 100% 16 mph 96 % 1019 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
14° | 16°°C 0.24 mm 24% 11 mph 89 % 1012 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
16° | 20°°C 0.06 mm 6% 13 mph 81 % 1012 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
21° | 24°°C 0 mm 0% 14 mph 67 % 1011 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
20° | 20°°C 0 mm 0% 11 mph 67 % 1010 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
18° | 18°°C 0 mm 0% 11 mph 84 % 1010 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
15° | 15°°C 0.2 mm 20% 11 mph 88 % 1008 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
14° | 14°°C 1 mm 100% 16 mph 92 % 1007 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
13° | 13°°C 0.8 mm 80% 14 mph 84 % 1008 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€95,134.48
-2.32%
Ethereum(ETH)
€2,248.91
-4.06%
Fesseln(USDT)
€0.88
0.03%
XRP(XRP)
€2.06
-3.55%
Solana(SOL)
€153.86
-4.09%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.201049
-6.86%
Shiba Inu(SHIB)
€0.000012
-6.62%
Pepe(PEPE)
€0.000012
-10.34%
Peanut das Eichhörnchen(PNUT)
€0.308269
-5.81%
Nach oben scrollen