WARPWIRE

MITRE ATT&CK: S1116 View on attack.mitre.org

Aliases: WARPWIRE

First seen
2023-05-01 00:00:00
Malware type
credential-stealer
Family
Malware family
Operating systems
network-devices
Last IoC activity
2026-07-21 08:36:00
Profile updated
2026-07-07 13:11:02

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

WARPWIRE is a Javascript credential stealer that targets plaintext passwords and usernames for exfiltration that was used during Cutting Edge to target Ivanti Connect Secure VPNs.

Detection coverage

  • 1 YARA rules
  • 39 Sigma rules

Malware & tools used

  • Compromise Host Software Binary (attack-pattern)
  • Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
  • JavaScript (attack-pattern)
  • Web Portal Capture (attack-pattern)
  • Standard Encoding (attack-pattern)

Used by threat actors

  • Cutting Edge (campaign)

Detection rules

  • SIGNATURE_BASE_M_Hunting_Credtheft_WARPWIRE_1 (yara-rule)

Reports & references

  • Mandiant — Suspected Apt Targets Ivanti Zero Day (report)
  • Mandiant — Investigating Ivanti Zero Day Exploitation (report)
  • MITRE ATT&CK — S1116 (report)

External references