LIGHTWIRE

MITRE ATT&CK: S1119 View on attack.mitre.org

Aliases: LIGHTWIRE

First seen
2023-06-01 00:00:00
Malware type
webshell
Family
Malware family
Operating systems
network-devices
Profile updated
2026-07-07 13:11:00

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

LIGHTWIRE is a web shell written in Perl that was used during Cutting Edge to maintain access and enable command execution by imbedding into the legitimate compcheckresult.cgi component of Ivanti Secure Connect VPNs.

Detection coverage

  • 2 YARA rules
  • 73 Sigma rules

Malware & tools used

  • Web Protocols (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Web Shell (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Compromise Host Software Binary (attack-pattern)

Used by threat actors

  • Cutting Edge (campaign)

Detection rules

  • SIGNATURE_BASE_M_Hunting_Webshell_LIGHTWIRE_2 (yara-rule)
  • SIGNATURE_BASE_M_Hunting_Dropper_THINSPOOL_1 (yara-rule)

Reports & references

  • Mandiant — Suspected Apt Targets Ivanti Zero Day (report)
  • Mandiant — Investigating Ivanti Zero Day Exploitation (report)
  • MITRE ATT&CK — S1119 (report)

External references