Hackers exploit Pulse Secure VPN flaws in sophisticated global campaign
Chinese-backed groups have been spying on US and European organisations including those in the defence industry


At least two major hacking groups have deployed a dozen malware families to exploit vulnerabilities in Pulse Connect Secure’s suite of virtual private network (VPN) devices to spy on the US defence sector.
Hackers infiltrated the Pulse Connect Secure (PCS) platform by exploiting CVE-2021-22893, a critical remote code execution flaw rated a maximum of ten on the threat severity scale, in combination with a number of previously discovered vulnerabilities.
Ivanti, Pulse Secure’s parent company, has released mitigations for the flaw, as well as a tool to determine if customer’s systems have been compromised, although a patch won’t be available until May 2021.
The purpose of the hack, and the scale of the infiltration, isn’t yet clear, but researchers with FireEye have linked the attack to Chinese state-backed groups. Although the predominant focus of their investigation was infiltration against US defence companies, researchers detected samples across the US and Europe.
They were first alerted to several intrusions at defence, government and financial organisations around the world earlier this year, based on the exploitation of Pulse Secure VPN devices. They weren’t able to determine how hackers obtained administrative rights to the appliances, although they now suspect Pulse Secure vulnerabilities from 2019 and 2020 were to blame, while other intrusions were due to CVE-2021-22893.
They identified two groups, referred to as UNC2630 and UNC2717, each conducting attacks during this period against US defence agencies and global government agencies respectively. They suspect that at least the former operates on behalf of the Chinese government, although there isn’t enough evidence to make a determination on the second.
FireEye has recommended that all Pulse Secure Connect customers should assess the impact of the available mitigations and apply them if possible. They should also use the most recent version of the Pulse Secure tool to detect whether their systems have been infiltrated.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Scott Caveza, research engineering manager with Tenable, said that alongside the new flaw, attackers also seem to be leveraging three previously fixed flaws including CVE-2019-11510, CVE-2020-8243 and CVE-2020-8260. The first of the three, which has been routinely exploited in the wild since it was first disclosed in August 2019, was among Tenable’s top five most commonly exploited flaws last year.
RELATED RESOURCE
“Because it is a zero-day and the timetable for the release of a patch is not yet known, CVE-2021-22893 gives attackers a valuable tool to gain entry into a key resource used by many organizations, especially in the wake of the shift to the remote workforce over the last year,” said Caveza.
“Attackers can utilise this flaw to further compromise the PCS device, implant backdoors and compromise credentials. While Pulse Secure has noted that the zero-day has seen limited use in targeted attacks, it’s just a matter of time before a proof-of-concept becomes publicly available, which we anticipate will lead to widespread exploitation, as we observed with CVE-2019-11510."
Trend Micro research previously found that attackers were heavily targeting VPNs, including exploiting flaws present in Fortinet's VPN and Pulse Connect Secure.

Keumars Afifi-Sabet is a writer and editor that specialises in public sector, cyber security, and cloud computing. He first joined ITPro as a staff writer in April 2018 and eventually became its Features Editor. Although a regular contributor to other tech sites in the past, these days you will find Keumars on LiveScience, where he runs its Technology section.
-
Google faces 'first of its kind' class action for search ads overcharging in UK
News Google faces a "first of its kind" £5 billion lawsuit in the UK over accusations it has a monopoly in digital advertising that allows it to overcharge customers.
By Nicole Kobie
-
Neural interfaces promise to make all tech accessible – it’s not that simple
Column Better consideration of ethics and practical implementation are needed if disabled people are to benefit from neural interfaces
By John Loeppky
-
Hackers are targeting Ivanti VPN users again – here’s what you need to know
News Ivanti has re-patched a security flaw in its Connect Secure VPN appliances that's been exploited by a China-linked espionage group since at least the middle of March.
By Emma Woollacott
-
Broadcom issues urgent alert over three VMware zero-days
News The firm says it has information to suggest all three are being exploited in the wild
By Solomon Klappholz
-
Nakivo backup flaw still present on some systems months after firms’ ‘silent patch’, researchers claim
News Over 200 vulnerable Nakivo backup instances have been identified months after the firm silently patched a security flaw.
By Solomon Klappholz
-
Everything you need to know about the Microsoft Power Pages vulnerability
News A severe Microsoft Power Pages vulnerability has been fixed after cyber criminals were found to have been exploiting unpatched systems in the wild.
By Solomon Klappholz
-
Vulnerability management complexity is leaving enterprises at serious risk
News Fragmented data and siloed processes mean remediation is taking too long
By Emma Woollacott
-
A critical Ivanti flaw is being exploited in the wild – here’s what you need to know
News Cyber criminals are actively exploiting a critical RCE flaw affecting Ivanti Connect Secure appliances
By Solomon Klappholz
-
Researchers claim an AMD security flaw could let hackers access encrypted data
News Using only a $10 test rig, researchers were able to pull off the badRAM attack
By Solomon Klappholz
-
A journey to cyber resilience
whitepaper DORA: Ushering in a new era of cyber security
By ITPro