China-Linked Threat Group UNC5221 Exploits Ivanti Vulnerability CVE-2025-22457 for Remote Code Execution and Malware Deployment in Enterprise Networks

A China-linked cyber-espionage group known as UNC5221 is actively exploiting a critical vulnerability in Ivanti’s Connect Secure and Policy Secure products, originally assessed as low-risk (CVE-2025-22457). The flaw allows remote code execution and has been used to deploy two newly discovered malware families—Trailblaze and Brushfire—on compromised systems. The threat group began exploitation shortly after Ivanti patched the flaw in February 2026. Mandiant and Ivanti have urged immediate upgrades and factory resets for affected devices. This attack highlights the growing trend of targeting edge security devices to gain privileged access into enterprise networks.

Apr 05, 2025 - 11:18
102.4k
China-Linked Threat Group UNC5221 Exploits Ivanti Vulnerability CVE-2025-22457 for Remote Code Execution and Malware Deployment in Enterprise Networks

Ivanti initially patched the CVE-2025-22457 vulnerability in February 2025 and labeled it as low risk. The flaw, a buffer overflow, was believed to only accept limited character input (periods and numbers), leading experts to think it could only enable a minor denial-of-service (DoS) attack.

However, by April 3, 2026, Ivanti revised this evaluation. New intelligence revealed that the vulnerability is, in fact, exploitable through advanced techniques, making remote code execution possible. As a result, Ivanti updated the flaw’s rating to a critical severity score of 9/10 on the CVSS scale.

Affected versions include:

  • Ivanti Connect Secure 22.7R2.5 and earlier

  • Ivanti Policy Secure

  • Ivanti ZTA gateways

  • Pulse Connect Secure 9.x (support ended on December 31, 2024)

Who Is Exploiting the Vulnerability?

The group exploiting the flaw has been identified as UNC5221, a China-nexus cyber-espionage actor. This group is known for targeting critical infrastructure and enterprise systems using zero-day vulnerabilities.

According to a joint investigation by Ivanti and Mandiant, UNC5221 began exploiting the vulnerability shortly after the February patch was released. By analyzing the differences between vulnerable and patched versions, the group discovered a way to weaponize the buffer overflow for remote code execution.

What Malware Is Being Dropped?

Mandiant observed UNC5221 deploying two new malware families on compromised systems:

  • Trailblaze – a stealthy, in-memory dropper that loads the second malware

  • Brushfire – a passive backdoor that enables persistent access

In addition to these, the group has also used familiar tools from past campaigns:

  • Spawnsloth – a log tampering tool

  • Spawnsnare – an encryption utility

  • Spawnant – a malware installer

These tools are used to maintain access, move laterally, and exfiltrate data while avoiding detection.

Ivanti’s Response and Recommendations

Ivanti urges all organizations using affected products to take the following steps immediately:

  • Upgrade to version 22.7R2.6 of Connect Secure, released in February.

  • Factory reset compromised appliances and reconfigure them from scratch using the updated version.

  • Migrate from Pulse Connect Secure 9.x, which is no longer supported.

  • Apply new patches for Policy Secure on April 21 and for ZTA Gateways on April 19.

The Bigger Picture: Why Attackers Target Edge Devices

Attacks like this reflect a broader trend in cyber threats. VPNs, firewalls, and edge devices often serve as privileged entry points into corporate networks. When attackers gain access to these devices, they can:

  • Bypass traditional security defenses

  • Establish persistent backdoors

  • Move laterally across networks

  • Launch wider ransomware or espionage campaigns

UNC5221 has repeatedly targeted Ivanti products, exploiting multiple zero-days:

  • CVE-2025-0282 and CVE-2025-0283 in Connect Secure VPNs (disclosed in January 2025)

  • CVE-2023-46805 and CVE-2024-21887 in earlier campaigns

The US Cybersecurity and Infrastructure Security Agency (CISA) also issued a warning about one of these vulnerabilities being used to deploy a malware named Resurge.

Conclusion

This case is a reminder that patching isn't just routine—it’s mission critical. Even flaws initially rated as low risk can become devastating if ignored. Organizations using Ivanti products must act quickly to patch vulnerable systems, check for signs of compromise, and implement better monitoring across edge devices. The exploitation of CVE-2025-22457 demonstrates how persistent, nation-state actors can weaponize even obscure vulnerabilities when given the opportunity.

FAQs

CVE-2025-22457 is a buffer overflow vulnerability in Ivanti Connect Secure, Policy Secure, and ZTA Gateway products that allows attackers to execute arbitrary code remotely.

UNC5221 is a China-linked advanced persistent threat (APT) group known for cyber-espionage campaigns targeting edge network devices.

Ivanti has upgraded its severity rating to 9/10 on the CVSS scale, marking it as a critical vulnerability due to its remote code execution capabilities.

Ivanti Connect Secure (versions 22.7R2.5 and earlier), Policy Secure, ZTA Gateways, and Pulse Connect Secure 9.x are affected.

Yes, Mandiant and Ivanti have confirmed that UNC5221 began exploiting the flaw soon after the initial patch was released.

UNC5221 has deployed new malware families—Trailblaze (a dropper) and Brushfire (a backdoor), along with older tools like Spawnsloth, Spawnsnare, and Spawnant.

Trailblaze is an in-memory dropper that executes malicious payloads without leaving persistent files on disk.

Brushfire is a passive backdoor that enables long-term unauthorized access to a compromised system.

They reverse-engineered the patch and found a sophisticated way to bypass character restrictions in the buffer to achieve code execution.

Ivanti urges users to upgrade to version 22.7R2.6, factory reset compromised systems, and apply upcoming patches for Policy Secure and ZTA Gateway.

No, support for Pulse Connect Secure 9.x ended on December 31, 2024, and affected users should migrate immediately.

Ivanti will patch Policy Secure on April 21 and automatically patch ZTA Gateways on April 19.

Yes, CISA has warned about active exploitation of Ivanti vulnerabilities in recent advisories.

Initially, Ivanti labeled the buffer overflow as low risk, assuming it couldn't be exploited for RCE.

Through forensic analysis of compromised systems and close collaboration with Ivanti.

They often have high privileges and access to internal networks, making them valuable entry points for attackers.

They exploited CVE-2025-0282, CVE-2025-0283, CVE-2023-46805, and CVE-2024-21887 in previous campaigns.

Spawnsloth is a log-tampering tool used to hide traces of the attack on compromised systems.

Spawnsnare is an encryption tool deployed by UNC5221 to obfuscate payloads or lock systems.

Spawnant is an installer used to deploy other malicious payloads on the system.

Yes, once attackers gain a foothold, they can move laterally across the network to access more sensitive systems.

RCE is a type of attack where the threat actor can run arbitrary commands on a remote system.

Ivanti’s original assessment underestimated the exploitability, but they have since issued corrections and patches.

Yes, Ivanti recommends a factory reset followed by a clean deployment using the patched version.

Traditional antivirus tools may miss these threats due to their stealthy, in-memory nature.

They should monitor unusual activity, use endpoint detection and response (EDR) tools, and apply the latest threat intelligence.

The Common Vulnerability Scoring System (CVSS) is a framework for rating the severity of security vulnerabilities.

It highlights the importance of timely patching and not underestimating vulnerabilities based on initial assumptions.

Unsupported versions are not eligible for security updates and are more vulnerable to known exploits.

No, it is part of a broader campaign of edge-device exploitation by advanced nation-state actors.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.