logo

Ivanti EPMM flaw exploited by Chinese hackers to breach govt agencies

ID: 766492e2-34f5-55c9-a1d2-a513317bec2f

STIX ID: report--766492e2-34f5-55c9-a1d2-a513317bec2f

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-05-22

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Chinese-linked UNC5221 has been observed exploiting an Ivanti Endpoint Manager Mobile zero-day (CVE-2025-4428) — alongside an authentication bypass (CVE-2025-4427) — to gain initial access to numerous government, healthcare, industrial, and corporate organizations globally; attackers conducted reconnaissance, deployed KrustyLoader and linked to the Auto-Color backdoor, exfiltrated data, and abused internal Office365 tokens and LDAP, with exploitation observed within days of the vendor patch and clear evidence of espionage-focused activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.