RESURGE Malware Exploits Ivanti Flaw with Rootkit and Web Shell Features
The new virus, RESURGE, was released as part of an exploitation campaign aimed at exploiting a security vulnerability in Ivanti Connect Secure (ICS) equipment that has since been fixed, according to information released by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
While RESURGE has some of the same features as the SPAWNCHIMERA malware strain, such as the ability to survive reboots, it also has unique commands that change how it behaves, the agency stated. The file has backdoor, bootkit, proxy, tunneler, dropper, and rootkit capabilities.
Ivanti Connect Secure, Policy Secure, and ZTA Gateways are susceptible to a stack-based buffer overflow vulnerability called CVE-2025-0282, which is linked to the malware's propagation and may allow remote code execution.
...

