Researchers studying cybersecurity are alerting people to a new malware known as DslogdRAT that was introduced after an Ivanti Connect Secure (ICS) security weakness was exploited and fixed.
According to a report released Thursday by JPCERT/CC researcher Yuma Masubuchi, the malware and a web shell were introduced during assaults against Japanese firms in December 2024 by taking use of a zero-day vulnerability known as CVE-2025-0282.
A serious security vulnerability in ICS known as CVE-2025-0282 may permit unauthenticated remote code execution. Ivanti addressed it at the beginning of January 2025.
However, a China-based cyber espionage gang called UNC5337 has taken use of the vulnerability as a zero-day to distribute the SPAWN malware ecosystem along with additional tools like DRYHOOK and PHASEJAM read more about DslogdRAT Malware Deployed via Ivanti ICS Zero-Day CVE-2025-0282 in Japan Attacks.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
