Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware LITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA

TLP:CLEAR
Family

AI Analysis

· 2 days ago

Executive Summary

UNC5325 leveraged LITTLELAMB.WOOLTEA as a backdoor against Ivanti Connect Secure VPN appliances, embedding itself in firmware updates to survive patching cycles. The malware enables remote command execution and facilitates secondary payload deployment across affected networks. Security teams should treat this threat with high urgency given its capability to persist on upgraded devices and stealth communication capabilities.

Enhanced Description

LITTLELAMB.WOOLTEA is a sophisticated backdoor that was first identified during the Mandiant Cutting Edge investigation of the UNC5325 adversary group in February 2024. The malware targets network devices, specifically Ivanti Connect Secure VPN servers, by exploiting vulnerabilities in their firmware update processes to gain foothold and maintain persistence on the target infrastructure. Once installed, LITTLELAMB.WOOLTEA establishes a covert channel with an external command‑and‑control (C2) server, enabling remote execution of arbitrary commands. The backdoor is engineered to survive system upgrades and patch cycles by modifying firmware integrity checks or by injecting itself into legitimate update packages, thereby evading conventional security mechanisms that rely on baseline image verification. In addition to persistence, the malware deploys secondary payloads—often additional ransomware or espionage components—across the compromised network. Its stealthy operation includes encrypted communications, privilege escalation on local devices, and the ability to scan internal networks for further vulnerable endpoints, expanding the adversary’s reach post‑compromise.

Key Capabilities

  • Establishes persistent backdoor via firmware update manipulation
  • Remote command and script execution through encrypted C2 channel
  • Deploys additional malware payloads within the network
  • Exploits Ivanti Connect Secure VPN vulnerabilities for initial access
  • Evades standard patch‑management detection by modifying integrity checks

ATT&CK Techniques

T1505.002 - Firmware Update
T1071.001 - Application Layer Protocol
T1059.001 - PowerShell
T1064 - Scripting
T1103 - Process Injection

Recommended Actions

  • Segment VPN servers from general corporate network and enforce strict least‑privilege access control
  • Apply all security patches immediately, verifying firmware hashes against vendor signatures
  • Deploy intrusion detection systems tuned to detect anomalous outbound traffic on uncommon ports or encrypted C2 patterns
  • Conduct comprehensive forensic analysis of VPN devices for hidden services or modified firmware

Suggested Tags

UNC5325
Cutting Edge
Ivanti Connect Secure
VPN Exploit
Backdoor
Persistence
Firmware Modification

Confidence Assessment

The intelligence is based solely on a high‑level description from the Mandiant report. Detailed technical data such as code samples, network signatures, and observable indicators of compromise are missing, limiting depth of analysis. Further investigation of network traffic logs, device integrity audits, and vendor patch information would improve confidence in threat profiling and mitigation strategies.

Description

LITTLELAMB.WOOLTEA is a backdoor that was used by UNC5325 during Cutting Edge to deploy malware on targeted Ivanti Connect Secure VPNs and to establish persistence across system upgrades and patches.(Citation: Mandiant Cutting Edge Part 3 February 2024)

Details

Type
Malware
Platforms
Network devices
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.