Critical Ivanti Connect Secure Vulnerability Exploited by China-linked Actor (Campaign)
ID: 222df8be-b1cb-5350-bee5-96c0024953d7
STIX ID: report--222df8be-b1cb-5350-bee5-96c0024953d7
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-04-03
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
On April 3, 2025 Ivanti disclosed CVE-2025-22457, a critical buffer‑overflow remote code execution flaw in Ivanti Connect Secure appliances that was exploited in the wild from mid‑March 2025 by a China‑linked actor (UNC5221). The threat actor deployed an in‑memory dropper (TRAILBLAZE), a passive backdoor (BRUSHFIRE), and SPAWN ecosystem components (SPAWNSLOTH, SPAWNSNARE, SPAWNWAVE) to perform stealthy, non‑persistent intrusions and post‑compromise actions such as log tampering and kernel extraction.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
