CISA Updates RESURGE Malware Analysis, Reveals Advanced Evasion Techniques
Summary
Hide ▲
Show ▼
CISA has released an updated Malware Analysis Report (MAR) on RESURGE, a sophisticated malware that exploits vulnerabilities to establish stealthy SSH-based command-and-control access. The malware can remain dormant on compromised Ivanti Connect Secure devices, evading routine detection. The updated analysis highlights RESURGE's advanced network-level evasion techniques, including forged TLS certificates and cryptographic methods, posing an ongoing threat to affected networks. CISA emphasizes the importance of using the provided indicators of compromise (IOCs) and detection signatures to identify and mitigate RESURGE, urging organizations to implement the recommended actions.
Timeline
-
26.02.2026 14:00 1 articles · 10h ago
CISA Updates RESURGE Malware Analysis with Advanced Evasion Techniques
CISA has released an updated Malware Analysis Report (MAR) on RESURGE, detailing its advanced network-level evasion techniques, including forged TLS certificates and cryptographic methods. The report highlights the malware's ability to remain dormant on compromised Ivanti Connect Secure devices, posing an ongoing threat. CISA provides updated IOCs and detection signatures to help organizations identify and mitigate RESURGE.
Show sources
- CISA Issues Updated RESURGE Malware Analysis Highlighting a Stealthy but Active Threat — www.cisa.gov — 26.02.2026 14:00
Information Snippets
-
RESURGE malware exploits vulnerabilities to gain covert SSH-based command-and-control access.
First reported: 26.02.2026 14:001 source, 1 articleShow sources
- CISA Issues Updated RESURGE Malware Analysis Highlighting a Stealthy but Active Threat — www.cisa.gov — 26.02.2026 14:00
-
The malware can remain dormant on compromised Ivanti Connect Secure devices, evading routine detection.
First reported: 26.02.2026 14:001 source, 1 articleShow sources
- CISA Issues Updated RESURGE Malware Analysis Highlighting a Stealthy but Active Threat — www.cisa.gov — 26.02.2026 14:00
-
RESURGE uses advanced network-level evasion techniques, including forged TLS certificates and cryptographic methods.
First reported: 26.02.2026 14:001 source, 1 articleShow sources
- CISA Issues Updated RESURGE Malware Analysis Highlighting a Stealthy but Active Threat — www.cisa.gov — 26.02.2026 14:00
-
CISA has provided updated IOCs and detection signatures to help organizations identify and mitigate RESURGE.
First reported: 26.02.2026 14:001 source, 1 articleShow sources
- CISA Issues Updated RESURGE Malware Analysis Highlighting a Stealthy but Active Threat — www.cisa.gov — 26.02.2026 14:00