malmoeb.bsky.social @malmoeb.bsky.social · Jun 21

1/ During various Ivanti Endpoint Manager Mobile investigations (CVE-2025-4428), we (as others in our field) saw that the threat actors dumped heap memory from the Tomcat Java processes using jcmd, in order to search the dumped data for sensitive information.

2 likes 1 replies

?

Replies

malmoeb.bsky.social · Jun 21

2/ Have others seen this behavior in other campaigns, from other actors? Dumping heap memory to steal sensitive information? Elastic, for example, does not have an (open source) rule for jcmd.