China-Linked Threat Group UNC5221 Exploits Ivanti Vulnerability CVE-2025-22457 for Remote Code Execution and Malware Deployment in Enterprise Networks
A China-linked cyber-espionage group known as UNC5221 is actively exploiting a critical vulnerability in Ivanti’s Connect Secure and Policy Secure products, originally assessed as low-risk (CVE-2025-22457). The flaw allows remote code execution and has been used to deploy two newly discovered malware families—Trailblaze and Brushfire—on compromised systems. The threat group began exploitation shortly after Ivanti patched the flaw in February 2026. Mandiant and Ivanti have urged immediate upgrades and factory resets for affected devices. This attack highlights the growing trend of targeting edge security devices to gain privileged access into enterprise networks.
Ivanti initially patched the CVE-2025-22457 vulnerability in February 2025 and labeled it as low risk. The flaw, a buffer overflow, was believed to only accept limited character input (periods and numbers), leading experts to think it could only enable a minor denial-of-service (DoS) attack.
However, by April 3, 2026, Ivanti revised this evaluation. New intelligence revealed that the vulnerability is, in fact, exploitable through advanced techniques, making remote code execution possible. As a result, Ivanti updated the flaw’s rating to a critical severity score of 9/10 on the CVSS scale.
Affected versions include:
-
Ivanti Connect Secure 22.7R2.5 and earlier
-
Ivanti Policy Secure
-
Ivanti ZTA gateways
-
Pulse Connect Secure 9.x (support ended on December 31, 2024)
Who Is Exploiting the Vulnerability?
The group exploiting the flaw has been identified as UNC5221, a China-nexus cyber-espionage actor. This group is known for targeting critical infrastructure and enterprise systems using zero-day vulnerabilities.
According to a joint investigation by Ivanti and Mandiant, UNC5221 began exploiting the vulnerability shortly after the February patch was released. By analyzing the differences between vulnerable and patched versions, the group discovered a way to weaponize the buffer overflow for remote code execution.
What Malware Is Being Dropped?
Mandiant observed UNC5221 deploying two new malware families on compromised systems:
-
Trailblaze – a stealthy, in-memory dropper that loads the second malware
-
Brushfire – a passive backdoor that enables persistent access
In addition to these, the group has also used familiar tools from past campaigns:
-
Spawnsloth – a log tampering tool
-
Spawnsnare – an encryption utility
-
Spawnant – a malware installer
These tools are used to maintain access, move laterally, and exfiltrate data while avoiding detection.
Ivanti’s Response and Recommendations
Ivanti urges all organizations using affected products to take the following steps immediately:
-
Upgrade to version 22.7R2.6 of Connect Secure, released in February.
-
Factory reset compromised appliances and reconfigure them from scratch using the updated version.
-
Migrate from Pulse Connect Secure 9.x, which is no longer supported.
-
Apply new patches for Policy Secure on April 21 and for ZTA Gateways on April 19.
The Bigger Picture: Why Attackers Target Edge Devices
Attacks like this reflect a broader trend in cyber threats. VPNs, firewalls, and edge devices often serve as privileged entry points into corporate networks. When attackers gain access to these devices, they can:
-
Bypass traditional security defenses
-
Establish persistent backdoors
-
Move laterally across networks
-
Launch wider ransomware or espionage campaigns
UNC5221 has repeatedly targeted Ivanti products, exploiting multiple zero-days:
-
CVE-2025-0282 and CVE-2025-0283 in Connect Secure VPNs (disclosed in January 2025)
-
CVE-2023-46805 and CVE-2024-21887 in earlier campaigns
The US Cybersecurity and Infrastructure Security Agency (CISA) also issued a warning about one of these vulnerabilities being used to deploy a malware named Resurge.
Conclusion
This case is a reminder that patching isn't just routine—it’s mission critical. Even flaws initially rated as low risk can become devastating if ignored. Organizations using Ivanti products must act quickly to patch vulnerable systems, check for signs of compromise, and implement better monitoring across edge devices. The exploitation of CVE-2025-22457 demonstrates how persistent, nation-state actors can weaponize even obscure vulnerabilities when given the opportunity.
FAQs
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0