β οΈ Security Advisory
Multiple vulnerabilities and malware activity related to RESURGE
Strongly recommends that users and administrators follow the guidance in this advisory.
Vulnerability / Malware Details
RESURGE Malware Analysis Report (CISA)
The Cybersecurity and Infrastructure Security Agency (CISA) has released a Malware Analysis Report (MAR) detailing a new malware variant, RESURGE, along with detection signatures. RESURGE inherits some capabilities from the SPAWNCHIMERA malware, such as persistence through reboots, but includes unique commands that change its behavior:
- Create web shells, manipulate integrity checks, and modify files.
- Use web shells for credential harvesting, account creation, password resets, and privilege escalation.
- Copy the web shell to the Ivanti running boot disk and manipulate the active coreboot image.
RESURGE has been linked to exploitation of CVE-2025-0282, a stack-based buffer overflow affecting Ivanti Connect Secure, Policy Secure, and ZTA Gateways. CISA added CVE-2025-0282 to its Known Exploited Vulnerabilities Catalog on January 8, 2025.
Additional Resources
- For malware details and YARA rules: MAR-25993211.R1.V1.CLEAR
- For a downloadable SIGMA detection rule: AR25-087A SIGMA YAML
Recommended Actions (in addition to CVE-2025-0282 mitigations)
- Perform a factory reset for the highest level of confidence.
- For cloud or virtual systems, reset using a known clean external image.
- See Ivantiβs recommended recovery steps for guidance.
Reset credentials for all accounts:
- Privileged and non-privileged accounts.
- All domain and local accounts, including Guest, HelpAssistant, DefaultAccount, System, Administrator, and krbtgt.
- Reset the krbtgt account twice, allowing replication between resets to avoid issues. Refer to CISAβs Eviction Guidance for more details.
Review and adjust access policies:
- Temporarily revoke or reduce privileges on affected devices/accounts.
- If intelligence collection is required, reduce access without alerting the attacker.
- Reset credentials or access keys for accounts with limited or non-elevated access.
Monitoring:
- Monitor accounts, particularly administrative ones, for signs of further unauthorized activity.