WIREFIRE — Malware Profile
WIREFIRE is a web shell written in Python that exists as trojanized logic to the visits.py component of Ivanti Connect Secure VPN appliances. WIREFIRE was used during Cutting Edge for downloading files and command execution.
MITRE ATT&CK techniques (7)
- T1071.001 Web Protocols
- T1105 Ingress Tool Transfer
- T1132.001 Standard Encoding
- T1140 Deobfuscate/Decode Files or Information
- T1505.003 Web Shell
- T1554 Compromise Host Software Binary
- T1573.001 Symmetric Cryptography
Attributed threat actors
- UNC5221 machine-inferred link