
🔐 China-Linked Hackers Weaponize Ivanti ICS Flaws to Unleash New MetaRAT Malware on Japanese Infrastructure
The threat landscape didn’t clock out for 2025 — it leveled up.
Japan’s shipping and transportation sector just got dragged into a full-scale cyber-espionage blitz, courtesy of a China-based threat actor abusing Ivanti Connect Secure edge vulnerabilities like it was their day job.
LAC’s Cyber Emergency Center confirmed that attackers exploited two high-severity Ivanti ICS vulnerabilities — CVE-2024-21893 (SSRF) and CVE-2024-21887 (command injection) — as their golden ticket inside. And once they got in?
They dropped a polished, nastier evolution of PlugX called MetaRAT and paired it with Talisman, another PlugX variant notorious in Asia-based espionage campaigns.
This wasn’t random. This was surgical.
🧬 The Attack Chain: Modern Espionage 101
Once the attackers landed inside Ivanti ICS devices, the dominoes fell fast:
1️⃣ Initial Access via Ivanti Zero-Days
These bugs allowed remote attackers to punch a tunnel straight through perimeter defenses — classic edge-device exploitation.
2️⃣ MetaRAT Deployment via DLL Side-Loading
MetaRAT isn’t your 2008 PlugX. It’s the glow-up version:
·AES-256-ECB encrypted configs
·Gzip-compressed comms
·Multi-protocol command channels (TCP, UDP, HTTP, HTTPS, ICMP)
·Custom HTTP “cookie” headers designed to blend into normal enterprise traffic
·Advanced plugins including keylogging + port-mapping for deep network tunneling
If PlugX is the OG malware toolkit… MetaRAT is the gym-bro version with upgraded performance enhancers.
3️⃣ Talisman Joins the Party
Another PlugX sibling, heavily modified with altered “Magic Values” to evade scanners.
Both strains shared code frameworks and even debug paths — meaning the same operator authored or customized the toolset.
4️⃣ Lateral Movement & Persistence
After initial access, attackers pivoted using stolen Active Directory creds.
Forensic logs showed:
·Spikes in Ivanti “ERR31093” errors
·Creation of suspicious DLLs and payload files
·Registry persistence keys like “matesile”
This wasn’t smash-and-grab. It was long-term access + long-term surveillance.
🕵️♂️ Why This Campaign Matters
This attack isn’t just another headline — it hits three critical truths:
✅ 1. Edge Devices Are Still the Easiest Way In
Firewalls, VPNs, Zero-Trust — none of it matters if your ICS gateway is unpatched.
✅ 2. Chinese Operators Are Upgrading, Fast
MetaRAT’s custom crypto and multi-protocol C2 show major investment and capability growth.
✅ 3. Critical Infrastructure Will Stay in the Crosshairs
Shipping. Transportation. Manufacturing. Energy.
If it moves, makes, or powers something — someone wants in.
🚨 High-Priority Indicators of Compromise (IOCs)
Security teams should look for:
🔑 Registry Keys
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\matesile
📁 Suspicious Files
mytilus3.dll
materoll
Keylogging files named VniFile.hlp
🌐 Network Traffic
HTTP requests containing Cookie-Yaga
HTTP requests containing Cookie-Nguy
Unexpected outbound traffic over ICMP, TCP, or UDP
⚠️ Elliptic Systems’ Take
This is exactly why patching edge devices needs to be treated like emergency surgery — not a “we’ll get to it Wednesday” errand.
PlugX isn’t going anywhere, and MetaRAT is the proof.
If attackers can weaponize ICS vulnerabilities this quickly, organizations need:
🔐 aggressive patch SLAs
🧠 UEBA for anomalous device activity
🛑 strict network segmentation
🚧 continuous monitoring on Ivanti Connect Secure appliances
Because when state-sponsored actors combine worth-a-fortune malware with unpatched perimeter systems, the outcome is always the same:
breach, persistence, and exfiltration on repeat.
