C0029: Cutting Edge
Cutting Edge was a campaign conducted by suspected China-nexus espionage actors, variously identified as UNC5221/UTA0178 and UNC5325, that began as early as December 2023 with the exploitation of zero-day vulnerabilities in Ivanti Connect Secure (previously Pulse Secure) VPN appliances. Cutting Edge targeted the U.S. defense industrial base and multiple sectors globally including telecommunications, financial, aerospace, and technology. Cutting Edge featured the use of defense evasion and living-off-the-land (LoTL) techniques along with the deployment of web shells and other custom malware.CitationMandiant Cutting Edge January 2024CitationVolexity Ivanti Zero-Day Exploitation January 2024CitationVolexity Ivanti Global Exploitation January 2024CitationMandiant Cutting Edge Part 2 January 2024CitationMandiant Cutting Edge Part 3 February 2024
Security context for executives and security teams
Cutting Edge matters because MITRE describes it as a campaign against externally facing Ivanti Connect Secure VPN appliances, followed by defense evasion, living-off-the-land activity, web shells, custom backdoors, credential capture, and lateral movement techniques. For leaders, the decision point is not only whether a VPN was patched, but whether the organization can prove the appliance was not modified, credentials were not harvested, and downstream Windows, Linux, macOS, ESXi, and network-device activity was reviewed where the related techniques apply.
Executive priority
Treat this as a remote-access infrastructure and identity-risk scenario. VPN appliances sit at the boundary between the internet and internal access, so compromise can affect business continuity, privileged access, incident scope, and audit evidence. Executives should ask whether externally exposed VPNs are inventoried, whether emergency vulnerability response includes appliance integrity checks, whether VPN credentials and sessions can be invalidated quickly, and whether SOC/IR teams can correlate VPN activity with Active Directory, RDP, SMB, SSH, and endpoint telemetry.
Technical view
ATT&CK provides no campaign-level detection text, so validation should be relationship-driven. Confirm visibility for Ivanti Connect Secure appliance changes and logs, especially around web shell/backdoor behaviors associated with ZIPLINE, WIREFIRE, WARPWIRE, GLASSTOKEN, BUSHWALK, LIGHTWIRE, FRAMESTING, LITTLELAMB.WOOLTEA, and PITSTOP. Hunt for command execution, file read/write, reverse shell or proxy-like network behavior, credential capture against VPN portals, and persistence across upgrades or patches where appliance evidence is available. Downstream, validate detections for LSASS and NTDS access, Impacket and CrackMapExec-like post-exploitation activity, RDP/SMB/SSH lateral movement, Python or script execution, process injection, encoded files, local data collection, keylogging/web portal capture, and indicator removal.
Likely telemetry
- Internet-facing VPN appliance inventory, version, configuration, and integrity evidence
- Ivanti Connect Secure web, authentication, administrative, and system logs where available
- File integrity or forensic evidence for modified CGI, Python, Perl, JavaScript, and package components on VPN appliances
- Network flow, proxy, DNS, and firewall telemetry for reverse shell, proxy, unusual egress, or appliance-to-internal connections
- VPN authentication records, session history, source IPs, and account usage patterns
Detection direction
- Do not rely on patch status alone; validate appliance integrity and historical logs because related malware includes web shells and backdoors embedded in legitimate components.
- Correlate VPN appliance activity with identity and lateral movement telemetry to determine whether compromise of remote access infrastructure led to internal access.
- Tune for suspicious use of RDP, SMB/admin shares, SSH, Impacket, and CrackMapExec-like behavior, but account for legitimate administrator and penetration-testing activity to reduce false positives.
- Prioritize detections for credential access paths named in the relationships: LSASS memory, NTDS, web portal capture, keylogging, and VPN credential theft patterns.
- Expect blind spots where network devices lack EDR-style logging, where appliance logs are overwritten, or where indicator removal has reduced forensic evidence.
Mitigation priorities
- Maintain a current inventory of externally exposed VPN and remote-access appliances, with ownership and emergency response contacts.
- Prioritize vulnerability management and emergency remediation for Ivanti Connect Secure and other internet-facing remote-access systems referenced by this campaign context.
- After suspected exposure, perform appliance integrity review and forensic validation before treating remediation as complete.
- Rotate or invalidate potentially exposed VPN credentials and sessions, and review privileged access paths tied to remote access.
- Restrict and monitor administrative protocols such as RDP, SMB/admin shares, and SSH, especially from VPN address ranges or appliance-originated connections.
Additional notes and limits
The campaign object names suspected China-nexus espionage actors and multiple targeted sectors, and describes zero-day exploitation of Ivanti Connect Secure VPN appliances beginning as early as December 2023. This take uses those official fields and the supplied ATT&CK relationships to frame defensive validation. Local exposure, compromise, and detection coverage must be established from asset inventory, appliance evidence, identity logs, and endpoint/network telemetry.
MITRE does not provide campaign-level detection guidance, campaign platforms, or tactics for this object. Several defensive recommendations are inferred from the supplied software and technique relationships rather than from explicit campaign detection text. This summary does not establish current activity, customer exposure, or guaranteed detectability.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Cutting Edge
Cutting Edge was a campaign conducted by suspected China-nexus espionage actors, variously identified as UNC5221/UTA0178 and UNC5325, that began as early as December 2023 with the exploitation of zero-day vulnerabilities in Ivanti Connect Secure (previously Pulse Secure) VPN appliances. Cutting Edge targeted the U.S. defense industrial base and multiple sectors globally including telecommunications, financial, aerospace, and technology. Cutting Edge featured the use of defense evasion and living-off-the-land (LoTL) techniques along with the deployment of web shells and other custom malware.CitationMandiant Cutting Edge January 2024CitationVolexity Ivanti Zero-Day Exploitation January 2024CitationVolexity Ivanti Global Exploitation January 2024CitationMandiant Cutting Edge Part 2 January 2024CitationMandiant Cutting Edge Part 3 February 2024
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
