[v7.5 Advisory] Threat Advisory: One threat actor responsible for 83% of recent Ivanti RCE attacks

ANALYST: BIVASH KUMAR NAYAK (CHIEF SECURITY ARCHITECT) • PUBLISHED: Sunday, 15 February 2026
TLP:CLEAR // CDB-SENTINEL-APEX-V7.5.1 // CONFIDENCE: MEDIUM

One threat actor responsible for 83% of recent Ivanti RCE attacks

Advisory ID: CDB-APEX-1771166123 | Risk Score: 7.5/10

1. Executive Summary (BLUF)

Threat intelligence observations show that a single threat actor is responsible for most of the active exploitation of two critical vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), tracked as CVE-2026-21962 and CVE-2026-24061. [...]...

Strategic Impact:

Infrastructure rotation suggests active adversary maintenance. High risk of data exfiltration for targeted sectors.

2. Analyst Insights & Crowdsourced Context

Community Intelligence:

"No specific community attribution found for this cluster."

Attribution Tags:
No tags identified.

3. Tactics, Techniques & Procedures (TTPs)

ID Technique Name Tactic
T1566PhishingInitial Access

4. Detection & Hunting Logic

Azure Sentinel (KQL)
DeviceNetworkEvents
| where RemoteUrl contains "suspicious-entity"
| summarize count() by DeviceName, RemoteUrl
Splunk Enterprise (SPL)
index=network_logs () | stats count by src_ip, dest_url

5. Adversary Infrastructure Topology

GLOBAL THREAT DISTRIBUTION

* Red pulses indicate active IoC origins triaged in this sweep.

CYBERDUDEBIVASH GOC // AUTONOMOUS SENTINEL NODE // CDB-APEX-1771166123
PROPRIETARY INTELLIGENCE PRODUCT. REDISTRIBUTION REQUIRES TLP:CLEAR CLEARANCE.