logo

Suspected China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457)

ID: bc2924fd-2f03-5a79-a8b2-a788b7267411

STIX ID: report--bc2924fd-2f03-5a79-a8b2-a788b7267411

Feed Name: Google Cloud Threat Intelligence

Threat Score
90/100

Date Published: 2025-04-03

Date Updated: 2026-04-27

Author: Mandiant

...
...

GTIG and Mandiant report active exploitation of Ivanti Connect Secure (CVE-2025-22457), a critical buffer-overflow RCE affecting ICS versions 22.7R2.5 and earlier; exploitation began mid-March 2025 and resulted in deployment of in-memory dropper TRAILBLAZE, passive backdoor BRUSHFIRE, and components of the SPAWN malware ecosystem, with attribution to suspected China-nexus actor UNC5221 and urgent patching and monitoring recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.