WIREFIRE

MITRE ATT&CK: S1115 View on attack.mitre.org

Aliases: GIFTEDVISITOR, WIREFIRE

First seen
2023-08-01 00:00:00
Malware type
webshell, trojan
Family
Malware family
Operating systems
network-devices
Profile updated
2026-07-07 13:10:55

Targeted industries: government-and-public-sector technology-and-telecommunications energy-and-utilities

Targeted regions: country_code:us country_code:ca country_code:gb

Context

WIREFIRE is a web shell written in Python that exists as trojanized logic to the visits.py component of Ivanti Connect Secure VPN appliances. WIREFIRE was used during Cutting Edge for downloading files and command execution.

Detection coverage

  • 1 YARA rules
  • 147 Sigma rules

Malware & tools used

  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Web Shell (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Web Protocols (attack-pattern)
  • Compromise Host Software Binary (attack-pattern)

Used by threat actors

  • Cutting Edge (campaign)

Detection rules

  • SIGNATURE_BASE_M_Hunting_Dropper_WIREFIRE_1 (yara-rule)

Reports & references

  • volexity.com — Active Exploitation Of Two Zero Day Vulnerabilities In Ivanti Connect Secure Vpn (report)
  • Mandiant — Suspected Apt Targets Ivanti Zero Day (report)
  • services.google.com — M Trends 2025 En (report)
  • malpedia.caad.fkie.fraunhofer.de — Py.Wirefire (report)
  • medium.com — Technical Deep Dive Understanding The Anatomy Of A Cyber Intrusion 080Bddc679F3 (report)
  • MITRE ATT&CK — S1115 (report)

External references