LIGHTWIRE

LIGHTWIRE is a web shell written in Perl that was used during Cutting Edge to maintain access and enable command execution by imbedding into the legitimate compcheckresult.cgi component of Ivanti Secure Connect VPNs.[1][2]

ID: S1119
Type: MALWARE
Platforms: Network
Version: 1.0
Created: 07 March 2024
Last Modified: 28 March 2024

Techniques Used

Domain ID Name Use
Enterprise T1554 主机软件二进制文件妥协

LIGHTWIRE can imbed itself into the legitimate compcheckresult.cgi component of Ivanti Connect Secure VPNs to enable command execution.[2][1]

Enterprise T1573 .001 加密通道: Symmetric Cryptography

LIGHTWIRE can RC4 encrypt C2 commands.[1]

Enterprise T1140 反混淆/解码文件或信息

LIGHTWIRE can RC4 decrypt and Base64 decode C2 commands.[1]

Enterprise T1071 .001 应用层协议: Web Protocols

LIGHTWIRE can use HTTP for C2 communications.[1]

Enterprise T1505 .003 服务器软件组件: Web Shell

LIGHTWIRE is a web shell capable of command execution and establishing persistence on compromised Ivanti Secure Connect VPNs.[1]

Campaigns

ID Name Description
C0029 Cutting Edge

[1]

References