MITRE said nation-state hackers breached its NERVE network via Ivanti zero-days

Organization
The MITRE Corporation
Exploit
Hacking
Industry
Nonprofit Research

The MITRE Corporation, the not-for-profit that operates several US federally funded research and development centers, said in April 2024 that it had detected suspicious activity on NERVE, its Networked Experimentation, Research and Virtualization Environment. NERVE is an unclassified collaborative network used for research, development and prototyping.

According to MITRE, a foreign nation-state actor began reconnaissance of its networks in January 2024, then exploited two Ivanti Connect Secure zero-day vulnerabilities, CVE-2023-46805 and CVE-2024-21887, against one of MITRE's virtual private networks. The attacker bypassed multi-factor authentication through session hijacking, moved laterally into MITRE's VMware infrastructure using a compromised administrator account, and planted backdoors and web shells to maintain access and harvest credentials.

MITRE took NERVE offline, brought in third-party forensic responders alongside its own team, and notified authorities and affected parties. It said there was no indication that its core enterprise network or partner systems had been affected. Chief technology officer Charles Clancy and cybersecurity engineer Lex Crumpton wrote that MITRE had believed its earlier mitigation steps were sufficient, adding that "these actions were clearly insufficient."

MITRE did not name the country behind the intrusion. The Hacker News reported that the same Ivanti flaws had been exploited by China-linked groups, including the actor Volexity tracks as UTA0178. Chief executive Jason Providakes said the organization was disclosing the incident "because of our commitment to operate in the public interest."

Sources