Ethical Hacking News
Malware Deployed Through Ivanti EPMM Flaws: A Growing Concern for Enterprise Security. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about the deployment of malware through Ivanti Endpoint Manager Mobile (EPMM) flaws, highlighting the growing concern for enterprise security.
Ivanti Endpoint Manager Mobile (EPMM) flaws have been exploited to deploy malware, posing a growing concern for enterprise security.CISA has issued warnings about two malware strains discovered in networks compromised via EPMM flaws CVE-2025-4427 and CVE-2025-4428.The vulnerabilities allow attackers to bypass authentication and execute arbitrary code on servers without proper credentials.Two malicious files have been analyzed by CISA, including web-install.jar and ReflectUtil.class, which enable attackers to inject and execute arbitrary code.CISA urges organizations to update to the latest version, monitor for suspicious activity, and restrict access to MDM systems to prevent attacks.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about the deployment of malware through Ivanti Endpoint Manager Mobile (EPMM) flaws, highlighting the growing concern for enterprise security. This alert comes on the heels of recent vulnerabilities in the EPMM software that were identified by CERT-EU, which have been exploited by threat actors to gain access to servers and execute malicious activities.
According to CISA, two malware strains were discovered in a network compromised via Ivanti EPMM flaws CVE-2025-4427 and CVE-2025-4428. These vulnerabilities, which have a CVSS score of 5.3 and 7.2 respectively, allow attackers to bypass authentication and execute arbitrary code on the compromised server without proper credentials.
The malware sets analyzed by CISA consist of two malicious files: web-install.jar, ReflectUtil.class, and SecurityHandlerWanListener.class for Set 1; and web-install.jar and WebAndroidAppInstaller.class for Set 2. Each set includes a loader and listener that enables attackers to inject and execute arbitrary code on the compromised server.
Set 1 uses a loader disguised as an Apache package to bypass restrictions and secretly install a malicious listener (SecurityHandlerWanListener) into Apache Tomcat, allowing attackers to run arbitrary code, maintain persistence, and exfiltrate data. Set 2 contains a loader posing as a MobileIron service that installs another malicious listener intercepting form-encoded HTTP requests, decrypts hidden parameters with a hard-coded AES key, builds and executes new classes, and then encrypts and returns the results.
Both malware sets provide attackers with powerful persistence, code execution, and data theft capabilities. CISA urges organizations to update to the latest version, monitor for suspicious activity, and restrict access to MDM systems to prevent attacks.
Furthermore, CISA shared YARA and SIGMA rules to detect the malware, along with MITRE ATT&CK techniques. These tools will help organizations identify and mitigate the threat posed by these malware families.
In light of this new alert, it is essential for organizations that use Ivanti EPMM software to take immediate action to address these vulnerabilities. This includes updating to the latest version of the software, implementing robust security measures, and monitoring for suspicious activity to prevent potential breaches.
As the landscape of cyber threats continues to evolve, it is crucial for organizations to stay vigilant and proactive in protecting their networks and data from malicious activities. CISA's warning highlights the importance of vigilance and swift action in addressing emerging vulnerabilities and mitigating the threat posed by these malware families.
Related Information:
https://www.ethicalhackingnews.com/articles/CISA-Warns-of-Malware-Deployed-Through-Ivanti-EPMM-Flaws-A-Growing-Concern-for-Enterprise-Security-ehn.shtml
https://securityaffairs.com/182350/malware/cisa-warns-of-malware-deployed-through-ivanti-epmm-flaws.html
https://nvd.nist.gov/vuln/detail/CVE-2025-4427
https://www.cvedetails.com/cve/CVE-2025-4427/
https://nvd.nist.gov/vuln/detail/CVE-2025-4428
https://www.cvedetails.com/cve/CVE-2025-4428/
https://www.cisa.gov/news-events/alerts/2025/09/18/cisa-releases-malware-analysis-report-malicious-listener-targeting-ivanti-endpoint-manager-mobile
https://www.securityweek.com/cisa-analyzes-malware-from-ivanti-epmm-intrusions/
Published: Sat Sep 20 10:57:39 2025 by llama3.2 3B Q4_K_M