[v7.5 Advisory] Threat Advisory: One threat actor responsible for 83% of recent Ivanti RCE attacks

ANALYST: BIVASH KUMAR NAYAK (CHIEF SECURITY ARCHITECT) • PUBLISHED: Sunday, 15 February 2026
TLP:CLEAR // CDB-SENTINEL-APEX-V7.5 // CONFIDENCE: MEDIUM

One threat actor responsible for 83% of recent Ivanti RCE attacks

ID: CDB-APEX-1771165560 | DATE: 1771165560 | CLASS: Cyber Threat Advisory

1. Executive Summary (BLUF)

Threat intelligence observations show that a single threat actor is responsible for most of the active exploitation of two critical vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), tracked as CVE-2026-21962 and CVE-2026-24061. [...]...

Impact: Significant risk to enterprise cloud infrastructure and credential integrity.

2. Tactics, Techniques & Procedures (TTPs)

ID Technique Tactic / Phase
T1566PhishingInitial Access

3. Indicators of Compromise (IOCs)

IPV4 ADDRESSES

No IPs identified

DOMAINS / HOSTS

No domains identified

4. Detection & Hunting Guidance

MICROSOFT SENTINEL (KQL)
DeviceNetworkEvents
| where RemoteUrl contains "suspicious-entity"
| summarize count() by DeviceName, RemoteUrl
SPLUNK (SPL)
index=network_logs () | stats count by src_ip, dest_url

5. Infrastructure Visualization

GLOBAL THREAT DISTRIBUTION

* Red pulses indicate active IoC origins triaged in this sweep.

THIS IS AN AUTONOMOUS INTELLIGENCE PRODUCT. VERIFY DATA BEFORE DEPLOYMENT.
© 2026 CYBERDUDEBIVASH PVT. LTD. // GLOBAL OPERATIONS CENTER