Suspected China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457)
ID: bc2924fd-2f03-5a79-a8b2-a788b7267411
STIX ID: report--bc2924fd-2f03-5a79-a8b2-a788b7267411
Feed Name: Google Cloud Threat Intelligence
Threat Score
GTIG and Mandiant report active exploitation of Ivanti Connect Secure (CVE-2025-22457), a critical buffer-overflow RCE affecting ICS versions 22.7R2.5 and earlier; exploitation began mid-March 2025 and resulted in deployment of in-memory dropper TRAILBLAZE, passive backdoor BRUSHFIRE, and components of the SPAWN malware ecosystem, with attribution to suspected China-nexus actor UNC5221 and urgent patching and monitoring recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
