Once inside, attackers deploy various malware families including RokRAT, which enables data exfiltration to legitimate cloud storage services, and PlugX, utilized by the TELEBOYi attack group for command and control operations. A sophisticated cyber espionage campaign has emerged targeting Japanese organizations through critical vulnerabilities in Ivanti Connect Secure and FortiGate VPN devices. Post-exploitation, the malware establishes persistence by modifying system registry entries and creating scheduled tasks that survive system reboots, ensuring continuous access to compromised networks for sustained espionage operations. The attack campaign, observed throughout fiscal year 2024, has primarily focused on manufacturing companies and government-related entities, with attackers exploiting CVE-2025-22457 in Ivanti systems and CVE-2024-55591 in FortiGate infrastructure. Security researchers have identified multiple threat groups orchestrating these attacks, including North Korean-affiliated actors and the MirrorFace group, which has been actively deploying the ANEL backdoor. Macnica analysts noted that the attackers have demonstrated sophisticated reconnaissance capabilities, progressing through system and network mapping phases using Living off the Land (LotL) techniques that leverage legitimate system tools to avoid detection. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. The campaign represents a significant escalation in targeted attacks against Japanese businesses, with threat actors successfully infiltrating overseas manufacturing bases through compromised VPN endpoints. The attack methodology begins with exploitation of unpatched VPN vulnerabilities, allowing threat actors to establish persistent access to corporate networks. The technical analysis reveals that attackers exploit the Ivanti Connect Secure vulnerability (CVE-2025-22457) by bypassing authentication mechanisms through crafted HTTP requests. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news. Tushar is a Cyber security content editor with a passion for creating captivating and informative content. These attacks have been particularly effective due to their strategic focus on external public assets that serve as entry points into corporate networks.
This Cyber News was published on cybersecuritynews.com. Publication date: Wed, 16 Jul 2025 10:00:25 +0000