Introduction to Malware Binary Triage (IMBT) Course
Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.
Enroll Now and Save 10%: Coupon Code MWNEWS10
Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.
What Is RESURGE Malware?
RESURGE is a 32-bit Linux shared object file that functions simultaneously as a backdoor, dropper, rootkit, and trojan. It is designed specifically for compromised Ivanti appliances and distinguishes itself through a fully passive command and control architecture. Unlike conventional implants that beacon to external servers and generate detectable outbound traffic, RESURGE remains silent. It does not initiate network connections. Instead, it embeds itself directly into Ivanti's native web server process, known as web, using process injection. From there, it monitors incoming TLS connections and activates only when it receives specially crafted traffic from an operator. During its dormant state, it produces no anomalous outbound activity, making detection through network monitoring significantly more difficult.
Article Link: RESURGE Malware Exploits Ivanti Connect Secure CVE-2025-0282 Vulnerability