LIGHTWIRE
MITRE ATT&CK: S1119 View on attack.mitre.org
Aliases: LIGHTWIRE
- First seen
- 2023-06-01 00:00:00
- Malware type
- webshell
- Family
- Malware family
- Operating systems
- network-devices
- Profile updated
- 2026-07-07 13:11:00
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
LIGHTWIRE is a web shell written in Perl that was used during Cutting Edge to maintain access and enable command execution by imbedding into the legitimate compcheckresult.cgi component of Ivanti Secure Connect VPNs.
Detection coverage
- 2 YARA rules
- 73 Sigma rules
Malware & tools used
- Web Protocols (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Web Shell (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Compromise Host Software Binary (attack-pattern)
Used by threat actors
- Cutting Edge (campaign)
Detection rules
- SIGNATURE_BASE_M_Hunting_Webshell_LIGHTWIRE_2 (yara-rule)
- SIGNATURE_BASE_M_Hunting_Dropper_THINSPOOL_1 (yara-rule)
Reports & references
- Mandiant — Suspected Apt Targets Ivanti Zero Day (report)
- Mandiant — Investigating Ivanti Zero Day Exploitation (report)
- MITRE ATT&CK — S1119 (report)