Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware BUSHWALK

BUSHWALK

TLP:CLEAR
Family

AI Analysis

· 5 hours ago

Executive Summary

BUSHWALK is a Perl web shell that injects malicious code into *querymanifest.cgi* on Ivanti Connect Secure VPN gateways, granting attackers persistent command execution and data exfiltration capabilities. The compromised gateway can be leveraged for lateral movement within the enterprise, posing significant credential compromise and network egress risks.

Enhanced Description

BUSHWALK is a Perl‑based web shell that attackers deployed by tampering with the legitimate *querymanifest.cgi* script on Ivanti Connect Secure VPN gateways during the so‑named Cutting Edge adversary campaigns reported in early 2024. By inserting malicious code into this CGI executable, threat actors gained persistent access to the internal network through a fully functional command interpreter that can execute arbitrary Perl commands via HTTP requests. The web shell delivers classic capabilities used by intrusion teams: it can read and write files on the VPN gateway, launch arbitrary system commands, exfiltrate sensitive data, and maintain stealth by exploiting the legitimate service path. Because the compromised component is a network‑edge appliance, adversaries can use BUSHWALK to pivot laterally into other internal hosts, enumerate connected devices, or compromise downstream services without triggering immediate alerts. Impact of this intrusion extends beyond the initially infected gateway: attackers obtain privileged access to VPN credentials and can intercept traffic between remote employees and corporate resources. The persistence mechanism—an altered CGI script that restarts automatically with the web server—makes remediation difficult if not detected promptly. Proper monitoring of file integrity on *querymanifest.cgi* and vigilant logging of its execution context are essential for early detection. In the broader threat landscape, BUSHWALK exemplifies a trend where adversaries weaponise legitimate application code to blend into normal traffic patterns, leveraging language interpreters like Perl to maintain lightweight, flexible footholds on network devices.

Key Capabilities

  • Persistent modification of querymanifest.cgi
  • Arbitrary Perl command execution via HTTP requests
  • File read/write operations on the VPN server
  • Data exfiltration over HTTPS
  • Stealth persistence by using legitimate web service

ATT&CK Techniques

T1059
T1105
T1608

Recommended Actions

  • Implement file integrity monitoring to detect unauthorized changes to querymanifest.cgi and related PHP/Perl scripts.
  • Patch or update Ivanti Connect Secure VPN firmware to the latest version, removing known vulnerable CGI handlers.
  • Configure WAF/IPS rules to block anomalous POST/GET requests targeting *querymanifest.cgi* and block outbound traffic from the gateway to untrusted IP ranges.
  • Segment VPN traffic with strict egress filters and monitor for high‑volume data transfers that could indicate exfiltration.
  • Perform routine vulnerability scans of network device configuration files and enforce least privilege on web service accounts.

Suggested Tags

Web Shell
Perl
Ivanti Connect Secure VPN
Querymanifest CGI
Cutting Edge Campaign
Network Device Compromise

Confidence Assessment

The analysis is based primarily on two Mandiant Cutting Edge reports, which confirm the presence of a Perl web shell within querymanifest.cgi on compromised Ivanti VPN gateways. While the exact command set invoked by BUSHWALK, its persistence beyond the modified CGI script, and any post‑exploitation lateral movement are not fully documented, confidence is high that the malware was inserted to provide remote code execution and data exfiltration capabilities.

Description

BUSHWALK is a web shell written in Perl that was inserted into the legitimate querymanifest.cgi file on compromised Ivanti Connect Secure VPNs during Cutting Edge.(Citation: Mandiant Cutting Edge Part 2 January 2024)(Citation: Mandiant Cutting Edge Part 3 February 2024)

Details

Type
Malware
Platforms
Network devices
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.