Meta tags:
Headings (most frequently used words):
phasejam, techniques, used, references, enterprise, layer,
Text of the page (most frequently used words):
the (22), phasejam (21), #enterprise (19), has (17), and (15), att (11), all (10), 2026 (8), ivanti (7), connect (7), secure (7), software (6), data (6), files (6), commands (6), ics (5), mobile (5), none (5), components (5), legitimate (5), appliance (5), shell (5), version (5), mitre (4), techniques (4), that (4), with (4), execution (4), compromised (4), network (4), base64 (4), command (4), remotedebug (4), used (4), execute (4), upgrades (4), upgrade (4), are (3), cti (3), defenses (3), april (3), dragos (3), appliances (3), cgi (3), web (3), actors (3), code (3), 003 (3), encoded (3), file (3), information (3), script (3), home (3), bin (3), ability (3), bash (3), modify (3), system (3), modified (3), corporation (2), use (2), domains (2), resources (2), reference (2), campaigns (2), groups (2), analytics (2), detection (2), strategies (2), assets (2), mitigations (2), tactics (2), matrices (2), core (2), objects (2), 2025 (2), january (2), retrieved (2), process (2), server (2), into (2), provided (2), threat (2), obfuscated (2), tool (2), linux (2), fake (2), html (2), progress (2), bar (2), device (2), dsupgrade (2), tools (2), decode (2), leveraged (2), s9014 (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, sub, john, wolfram, josh, murchie, matt, lin, daniel, ainsworth, robert, wallace, dimiter, andonov, dhanesh, kizhakkinan, jacob, thompson, vpn, targeted, new, zero, day, exploitation, march, cybersecurity, report, year, review, petrochemicals, focus, references, disabled, service, stop, t1489, inserted, perl, based, shells, remote, access, capabilities, component, t1505, launched, webshell, using, module, decoded, mime, encrypted, 013, obfuscation, 010, t1027, renamed, allowing, threats, write, malicious, bak, rename, utilities, masquerading, t1036, upload, onto, ingress, transfer, t1105, exfiltrate, from, victim, exfiltration, over, channel, t1041, via, also, stream, editor, sed, unix, configuration, modification, event, triggered, 004, t1546, prevented, intercepting, rendering, through, function, called, which, allowed, remain, under, control, adversary, processupgradedisplay, spoof, blocks, altering, disable, t1685, deobfuscate, t1140, within, its, generate, mimics, running, sleep, delay, t1678, blocked, systems, falsely, indicates, successful, while, operating, older, manipulation, t1565, enable, persistence, including, inserting, modifying, block, overwriting, arbitrary, when, specific, parameters, restauth, getcomponent, compromise, host, binary, t1554, native, associated, cli, scripting, interpreter, 008, t1059, name, domain, view, download, layer, navigator, layers, live, permalink, may, last, created, intelligence, contributors, devices, platforms, malware, type, dropper, written, modifies, was, first, reported, previously, been, people, republic, china, prc, affiliated, identified, unc5221, sylvanite, open, join, october, mclean, for, hotel, location, details, can, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, advisory, council, learn, more, about, get, started, detections,
Text of the page (random words):
phasejam software s9014 mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home software phasejam phasejam phasejam is a dropper written as a bash shell script that modifies ivanti connect secure appliance components phasejam was first reported in january 2025 phasejam has previously been leveraged by people s republic of china prc affiliated actors identified as unc5221 and sylvanite 1 2 id s9014 ⓘ type malware ⓘ platforms linux network devices contributors dragos threat intelligence version 1 0 created 16 april 2026 last modified 12 may 2026 version permalink live version att ck navigator layers enterprise layer download view techniques used domain id name use enterprise t1059 008 command and scripting interpreter network device cli phasejam has leveraged native commands associated with the compromised network appliance to execute code 2 enterprise t1554 compromise host software binary phasejam has modified legitimate components to enable persistence and execution including inserting a web shell into getcomponent cgi and restauth cgi modifying dsupgrade pm to block system upgrades and overwriting remotedebug to execute arbitrary commands when specific parameters are provided 2 enterprise t1565 data manipulation phasejam has blocked legitimate upgrades of ivanti connect secure systems and falsely indicates a successful upgrade while operating on an older version 2 enterprise t1678 delay execution phasejam has used the sleep command within its code to generate a fake html upgrade progress bar that mimics a running process 2 enterprise t1140 deobfuscate decode files or information phasejam has the ability to decode base64 commands and data 2 enterprise t1685 disable or modify tools phasejam has modified ivanti connect secure appliances and blocks the system upgrades by altering the dsupgrade pm file 2 003 modify or spoof tool ui phasejam has prevented legitimate ivanti connect secure system upgrades by intercepting the upgrade command and rendering fake html upgrade progress bar through a function called processupgradedisplay which allowed the compromised device to remain under the control of the adversary 2 enterprise t1546 004 event triggered execution unix shell configuration modification phasejam has used a bash script to modify components on ivanti connect secure appliances and execute files via bin bash 1 it has also used the linux stream editor sed to execute commands 2 enterprise t1041 exfiltration over c2 channel phasejam has the ability to exfiltrate data from the victim appliance 2 enterprise t1105 ingress tool transfer phasejam has the ability to upload files onto the compromised appliance 2 enterprise t1036 003 masquerading rename legitimate utilities phasejam has renamed the file home bin remotedebug to remotedebug bak allowing the threats actors to write a malicious home bin remotedebug shell script 2 enterprise t1027 010 obfuscated files or information command obfuscation phasejam has encoded commands with base64 2 013 obfuscated files or information encrypted encoded file phasejam has launched a webshell using the mime base64 module that encoded and decoded base64 commands 2 enterprise t1505 003 server software component web shell phasejam has inserted perl based web shells into legitimate files that provided threat actors with remote access and code execution capabilities on the compromised network appliance 2 enterprise t1489 service stop phasejam has disabled the cgi server process on ivanti connect secure appliances 2 references dragos 2026 march 24 dragos 2026 ot cybersecurity report year in review o g and petrochemicals focus retrieved april 17 2026 john wolfram josh murchie matt lin daniel ainsworth robert wallace dimiter andonov dhanesh kizhakkinan jacob thompson 2025 january 8 ivanti connect secure vpn targeted in new zero day exploitation retrieved april 14 2026 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|