GLASSTOKEN — Malware Profile
GLASSTOKEN is a custom web shell used by threat actors during Cutting Edge to execute commands on compromised Ivanti Secure Connect VPNs.
MITRE ATT&CK techniques (4)
- T1059.001 PowerShell
- T1132.001 Standard Encoding
- T1140 Deobfuscate/Decode Files or Information
- T1505.003 Web Shell
Attributed threat actors
- UNC5221 machine-inferred link