Coordinated Reconnaissance and Exploitation Activity Targeting Edge VPN Appliances
CISA issued updated technical details on RESURGE, a stealthy implant used in zero-day intrusions of Ivanti Connect Secure appliances via CVE-2025-0282. The malware (a 32-bit Linux shared object, libdsupgrade.so) is designed for long-term persistence and covert access, with capabilities described as including rootkit/bootkit-style functionality, credential theft via webshells, account manipulation, privilege escalation, and tunneling/proxying. CISA highlighted that RESURGE can remain dormant and evade detection by acting as a passive C2: rather than beaconing out, it waits for specific inbound TLS connections and, when loaded under the web process, hooks accept() to inspect TLS packets and only activate on attacker-identified traffic (using a CRC32-based TLS fingerprinting approach); non-matching traffic is passed through to the legitimate service. Reporting cited Mandiant’s attribution of the early exploitation activity to a China-linked actor tracked as UNC5221, with zero-day exploitation reported since mid-December 2024.
Separately, GreyNoise reported a large-scale reconnaissance campaign against SonicWall SonicOS/SSL VPN infrastructure (84,142 scanning sessions over several days) focused primarily on enumerating whether SSL VPN is enabled by probing a single API endpoint—behavior consistent with pre-attack target mapping rather than immediate CVE exploitation. The activity came from thousands of IPs across multiple ASNs and included heavy use of commercial proxy infrastructure (rotating exits) in short, concentrated bursts, a pattern GreyNoise assessed as coordinated and operationally segmented. GreyNoise assessed this recon as a precursor to credential-based intrusion and ransomware operations frequently associated with edge VPN access (citing Akira and Fog as examples), and noted broad internet exposure and a meaningful population of devices running vulnerable or unsupported firmware—conditions that increase the likelihood that reconnaissance will translate into follow-on compromise attempts.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
5 events from the most recent confirmed update back to the earliest known activity.
GreyNoise discloses findings on SonicWall reconnaissance infrastructure
On February 27, 2026, GreyNoise published its analysis attributing the SonicWall reconnaissance to several distinct infrastructure clusters, including ByteZero-backed proxy rotation, a Netherlands-based scanner fleet, a mega-scanner IP, and a NetExtender credential-testing cluster. It warned the activity could precede exploitation and urged defenders to restrict exposure, enforce MFA, and patch SonicOS, especially for CVE-2024-53704.
CISA publishes updated technical analysis of RESURGE malware
On February 27, 2026, CISA released updated technical details on the RESURGE implant used in Ivanti Connect Secure compromises. The update highlighted its dormant operation, persistence across reboots, covert TLS-based communications, and related tooling including a SpawnSloth variant and a kernel extraction script supporting boot-level persistence.
Mass reconnaissance campaign targets SonicWall SSL VPN exposure
Between February 22 and 25, 2026, GreyNoise observed 84,142 scanning sessions from 4,305 IPs targeting SonicWall SonicOS devices. The activity primarily enumerated whether SSL VPN was enabled via a REST API endpoint, a likely precursor to credential attacks and ransomware initial access.
ByteZero proxy management platform reportedly goes offline
GreyNoise noted that the management platform for the commercial proxy service ByteZero reportedly went offline in December 2025. This reportedly reduced oversight of infrastructure later used in SonicWall reconnaissance activity.
UNC5221 begins zero-day exploitation of Ivanti CVE-2025-0282
Mandiant assessed that the China-linked threat actor UNC5221 started exploiting CVE-2025-0282 as a zero-day against Ivanti Connect Secure devices in mid-December 2024. The activity deployed the RESURGE malware implant to establish persistent access on compromised systems.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
2 references tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


