Cybersecurity

🔐 China-Linked Hackers Weaponize Ivanti ICS Flaws to Unleash New MetaRAT Malware on Japanese Infrastructure

December 14, 20253 min read

The threat landscape didn’t clock out for 2025 — it leveled up.
Japan’s shipping and transportation sector just got dragged into a full-scale cyber-espionage blitz, courtesy of a China-based threat actor abusing Ivanti Connect Secure edge vulnerabilities like it was their day job.

LAC’s Cyber Emergency Center confirmed that attackers exploited two high-severity Ivanti ICS vulnerabilities — CVE-2024-21893 (SSRF) and CVE-2024-21887 (command injection) — as their golden ticket inside. And once they got in?
They dropped a polished, nastier evolution of PlugX called MetaRAT and paired it with Talisman, another PlugX variant notorious in Asia-based espionage campaigns.

This wasn’t random. This was surgical.

🧬 The Attack Chain: Modern Espionage 101

Once the attackers landed inside Ivanti ICS devices, the dominoes fell fast:

1️ Initial Access via Ivanti Zero-Days

These bugs allowed remote attackers to punch a tunnel straight through perimeter defenses — classic edge-device exploitation.

2️ MetaRAT Deployment via DLL Side-Loading

MetaRAT isn’t your 2008 PlugX. It’s the glow-up version:

·AES-256-ECB encrypted configs

·Gzip-compressed comms

·Multi-protocol command channels (TCP, UDP, HTTP, HTTPS, ICMP)

·Custom HTTP “cookie” headers designed to blend into normal enterprise traffic

·Advanced plugins including keylogging + port-mapping for deep network tunneling

If PlugX is the OG malware toolkit… MetaRAT is the gym-bro version with upgraded performance enhancers.

3️ Talisman Joins the Party

Another PlugX sibling, heavily modified with altered “Magic Values” to evade scanners.


Both strains shared code frameworks and even debug paths — meaning the same operator authored or customized the toolset.

4️ Lateral Movement & Persistence

After initial access, attackers pivoted using stolen Active Directory creds.

Forensic logs showed:

·Spikes in Ivanti “ERR31093” errors

·Creation of suspicious DLLs and payload files

·Registry persistence keys like “matesile”

This wasn’t smash-and-grab. It was long-term access + long-term surveillance.


🕵️‍♂️ Why This Campaign Matters

This attack isn’t just another headline — it hits three critical truths:

1. Edge Devices Are Still the Easiest Way In

Firewalls, VPNs, Zero-Trust — none of it matters if your ICS gateway is unpatched.

2. Chinese Operators Are Upgrading, Fast

MetaRAT’s custom crypto and multi-protocol C2 show major investment and capability growth.

3. Critical Infrastructure Will Stay in the Crosshairs

Shipping. Transportation. Manufacturing. Energy.

If it moves, makes, or powers something — someone wants in.


🚨 High-Priority Indicators of Compromise (IOCs)

Security teams should look for:

🔑 Registry Keys

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\matesile

📁 Suspicious Files

  • mytilus3.dll

  • materoll

  • Keylogging files named VniFile.hlp

🌐 Network Traffic

  • HTTP requests containing Cookie-Yaga

  • HTTP requests containing Cookie-Nguy

  • Unexpected outbound traffic over ICMP, TCP, or UDP


⚠️ Elliptic Systems’ Take

This is exactly why patching edge devices needs to be treated like emergency surgery — not a “we’ll get to it Wednesday” errand.


PlugX isn’t going anywhere, and MetaRAT is the proof.


If attackers can weaponize ICS vulnerabilities this quickly, organizations need:


🔐 aggressive patch SLAs
🧠 UEBA for anomalous device activity
🛑 strict network segmentation
🚧 continuous monitoring on Ivanti Connect Secure appliances

Because when state-sponsored actors combine worth-a-fortune malware with unpatched perimeter systems, the outcome is always the same:


breach, persistence, and exfiltration on repeat.

Eric Stefanik

Eric Stefanik

Ai Consultant | Best-selling Author | Speaker | Innovator | Leading Cybersecurity Expert

LinkedIn logo icon
Instagram logo icon
Youtube logo icon
Back to Blog