WIREFIRE
MITRE ATT&CK: S1115 View on attack.mitre.org
Aliases: GIFTEDVISITOR, WIREFIRE
- First seen
- 2023-08-01 00:00:00
- Malware type
- webshell, trojan
- Family
- Malware family
- Operating systems
- network-devices
- Profile updated
- 2026-07-07 13:10:55
Targeted industries: government-and-public-sector technology-and-telecommunications energy-and-utilities
Targeted regions: country_code:us country_code:ca country_code:gb
Context
WIREFIRE is a web shell written in Python that exists as trojanized logic to the visits.py component of Ivanti Connect Secure VPN appliances. WIREFIRE was used during Cutting Edge for downloading files and command execution.
Detection coverage
- 1 YARA rules
- 147 Sigma rules
Malware & tools used
- Deobfuscate/Decode Files or Information (attack-pattern)
- Web Shell (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Standard Encoding (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Web Protocols (attack-pattern)
- Compromise Host Software Binary (attack-pattern)
Used by threat actors
- Cutting Edge (campaign)
Detection rules
- SIGNATURE_BASE_M_Hunting_Dropper_WIREFIRE_1 (yara-rule)
Reports & references
- volexity.com — Active Exploitation Of Two Zero Day Vulnerabilities In Ivanti Connect Secure Vpn (report)
- Mandiant — Suspected Apt Targets Ivanti Zero Day (report)
- services.google.com — M Trends 2025 En (report)
- malpedia.caad.fkie.fraunhofer.de — Py.Wirefire (report)
- medium.com — Technical Deep Dive Understanding The Anatomy Of A Cyber Intrusion 080Bddc679F3 (report)
- MITRE ATT&CK — S1115 (report)