logo

China-Linked Threat Group Exploits Ivanti Bug

ID: 173487c8-91a6-53b7-b2ab-11eafbb1db75

STIX ID: report--173487c8-91a6-53b7-b2ab-11eafbb1db75

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2025-04-03

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

A China-nexus cyber-espionage actor identified as UNC5221 is actively exploiting a critical buffer overflow (CVE-2025-22457) in Ivanti Connect Secure, Pulse Connect Secure and related gateways to achieve remote code execution; the group drops two new malware families (Trailblaze — an in-memory dropper — and Brushfire — a passive backdoor) along with additional toolset components. Ivanti and Mandiant confirmed exploitation in the wild, Ivanti raised the vulnerability to CVSS 9.0, and organizations are urged to upgrade, patch, or factory-reset compromised appliances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.