DslogdRAT Malware Exploits Ivanti Connect Secure Zero-Day Vulnerability

Amber | Attack Report
Download PDF

A stealthy attack hit Japanese organizations in December 2024, exploiting a zero-day flaw (CVE-2025-0282) to silently deploy DslogdRAT malware. Using a hidden Perl-based web shell, the attackers gained control, with DslogdRAT quietly reaching out to its command server, executing commands, and blending into normal operations by only running during business hours.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox