Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
perimeter-device-exposureactively-exploited-vulnerabilityremote-access-implantcommand-and-control-method

Coordinated Reconnaissance and Exploitation Activity Targeting Edge VPN Appliances

Updated 3mo agoFirst seen Mar 1, 20262 sources

CISA issued updated technical details on RESURGE, a stealthy implant used in zero-day intrusions of Ivanti Connect Secure appliances via CVE-2025-0282. The malware (a 32-bit Linux shared object, libdsupgrade.so) is designed for long-term persistence and covert access, with capabilities described as including rootkit/bootkit-style functionality, credential theft via webshells, account manipulation, privilege escalation, and tunneling/proxying. CISA highlighted that RESURGE can remain dormant and evade detection by acting as a passive C2: rather than beaconing out, it waits for specific inbound TLS connections and, when loaded under the web process, hooks accept() to inspect TLS packets and only activate on attacker-identified traffic (using a CRC32-based TLS fingerprinting approach); non-matching traffic is passed through to the legitimate service. Reporting cited Mandiant’s attribution of the early exploitation activity to a China-linked actor tracked as UNC5221, with zero-day exploitation reported since mid-December 2024.

Separately, GreyNoise reported a large-scale reconnaissance campaign against SonicWall SonicOS/SSL VPN infrastructure (84,142 scanning sessions over several days) focused primarily on enumerating whether SSL VPN is enabled by probing a single API endpoint—behavior consistent with pre-attack target mapping rather than immediate CVE exploitation. The activity came from thousands of IPs across multiple ASNs and included heavy use of commercial proxy infrastructure (rotating exits) in short, concentrated bursts, a pattern GreyNoise assessed as coordinated and operationally segmented. GreyNoise assessed this recon as a precursor to credential-based intrusion and ransomware operations frequently associated with edge VPN access (citing Akira and Fog as examples), and noted broad internet exposure and a meaningful population of devices running vulnerable or unsupported firmware—conditions that increase the likelihood that reconnaissance will translate into follow-on compromise attempts.

Share:
Coordinated Reconnaissance and Exploitation Activity Targeting Edge VPN Appliances
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 27, 20264mo ago

GreyNoise discloses findings on SonicWall reconnaissance infrastructure

On February 27, 2026, GreyNoise published its analysis attributing the SonicWall reconnaissance to several distinct infrastructure clusters, including ByteZero-backed proxy rotation, a Netherlands-based scanner fleet, a mega-scanner IP, and a NetExtender credential-testing cluster. It warned the activity could precede exploitation and urged defenders to restrict exposure, enforce MFA, and patch SonicOS, especially for CVE-2024-53704.

CISA publishes updated technical analysis of RESURGE malware

On February 27, 2026, CISA released updated technical details on the RESURGE implant used in Ivanti Connect Secure compromises. The update highlighted its dormant operation, persistence across reboots, covert TLS-based communications, and related tooling including a SpawnSloth variant and a kernel extraction script supporting boot-level persistence.

Feb 22, 20264mo ago

Mass reconnaissance campaign targets SonicWall SSL VPN exposure

Between February 22 and 25, 2026, GreyNoise observed 84,142 scanning sessions from 4,305 IPs targeting SonicWall SonicOS devices. The activity primarily enumerated whether SSL VPN was enabled via a REST API endpoint, a likely precursor to credential attacks and ransomware initial access.

Dec 15, 20256mo ago

ByteZero proxy management platform reportedly goes offline

GreyNoise noted that the management platform for the commercial proxy service ByteZero reportedly went offline in December 2025. This reportedly reduced oversight of infrastructure later used in SonicWall reconnaissance activity.

Dec 15, 20242y ago

UNC5221 begins zero-day exploitation of Ivanti CVE-2025-0282

Mandiant assessed that the China-linked threat actor UNC5221 started exploiting CVE-2025-0282 as a zero-day against Ivanti Connect Secure devices in mid-December 2024. The activity deployed the RESURGE malware implant to establish persistent access on compromised systems.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

22 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.