RESURGE Malware Investigation Exposes a Quiet but Actively Operating Threat

Published: 15/03/2026 10:42 PM Category: Alert CVE: CVE-2025-0282
HIGH SEVERITY

⚠️ Security Advisory

Multiple vulnerabilities and malware activity related to RESURGE

Strongly recommends that users and administrators follow the guidance in this advisory.

Vulnerability / Malware Details

RESURGE Malware Analysis Report (CISA)

The Cybersecurity and Infrastructure Security Agency (CISA) has released a Malware Analysis Report (MAR) detailing a new malware variant, RESURGE, along with detection signatures. RESURGE inherits some capabilities from the SPAWNCHIMERA malware, such as persistence through reboots, but includes unique commands that change its behavior:

  • Create web shells, manipulate integrity checks, and modify files.
  • Use web shells for credential harvesting, account creation, password resets, and privilege escalation.
  • Copy the web shell to the Ivanti running boot disk and manipulate the active coreboot image.

RESURGE has been linked to exploitation of CVE-2025-0282, a stack-based buffer overflow affecting Ivanti Connect Secure, Policy Secure, and ZTA Gateways. CISA added CVE-2025-0282 to its Known Exploited Vulnerabilities Catalog on January 8, 2025.

Additional Resources

  • For malware details and YARA rules: MAR-25993211.R1.V1.CLEAR
  • For a downloadable SIGMA detection rule: AR25-087A SIGMA YAML

Recommended Actions (in addition to CVE-2025-0282 mitigations)

  • Perform a factory reset for the highest level of confidence.
  • For cloud or virtual systems, reset using a known clean external image.
  • See Ivanti’s recommended recovery steps for guidance.

Reset credentials for all accounts:

  • Privileged and non-privileged accounts.
  • All domain and local accounts, including Guest, HelpAssistant, DefaultAccount, System, Administrator, and krbtgt.
  • Reset the krbtgt account twice, allowing replication between resets to avoid issues. Refer to CISA’s Eviction Guidance for more details.

Review and adjust access policies:

  • Temporarily revoke or reduce privileges on affected devices/accounts.
  • If intelligence collection is required, reduce access without alerting the attacker.
  • Reset credentials or access keys for accounts with limited or non-elevated access.

Monitoring:

  • Monitor accounts, particularly administrative ones, for signs of further unauthorized activity.

Reference

https://www.cisa.gov/news-events/alerts/2025/03/28/cisa-releases-malware-analysis-report-resurge-malware-associated-ivanti-connect-secure