Ivanti disclosed a critical security vulnerability, CVE-2025-22457, affecting its Connect Secure (ICS) VPN appliances.
The flaw, identified as a buffer overflow vulnerability, enables remote code execution upon successful exploitation.
Mandiant and Ivanti have confirmed active exploitation of this vulnerability in ICS versions 22.7R2.5 and earlier, as well as the end-of-life ICS 9.X versions.
The earliest signs of exploitation date back to mid-March 2025, with attackers deploying malware families such as TRAILBLAZE and BRUSHFIRE alongside the SPAWN malware ecosystem attributed to UNC5221, a suspected China-nexus espionage group.
Post-Exploitation Malware Deployment
UNC5221 leveraged the CVE-2025-22457 vulnerability to deploy advanced malware through a shell script dropper.
The first stage involves injecting the TRAILBLAZE in-memory dropper into a running web process, followed by deploying the BRUSHFIRE passive backdoor.
TRAILBLAZE is a minimalistic dropper written in bare C that uses raw system calls for injection, ensuring stealth and efficiency.
BRUSHFIRE operates as an SSL_read hook, decrypting and executing shellcode embedded in incoming data streams while maintaining non-persistent functionality.
The SPAWN ecosystem of malware further complicates detection and mitigation efforts.
Components such as SPAWNSLOTH tamper with logging mechanisms to evade monitoring, while SPAWNSNARE extracts and encrypts Linux kernel images using AES encryption.
SPAWNWAVE combines capabilities from multiple malware families to enhance operational effectiveness.
Attribution and Broader Implications
The Google Threat Intelligence Group (GTIG) has attributed these attacks to UNC5221 based on their history of exploiting zero-day vulnerabilities in edge devices since 2023.
UNC5221 has previously targeted NetScaler ADCs, Cyberoam appliances, QNAP devices, and ASUS routers to mask their intrusion sources.
Their aggressive operational tempo and deep knowledge of edge infrastructure highlight their persistent focus on exploiting both zero-day and n-day vulnerabilities.
This campaign underscores the sophistication of China-nexus espionage actors who invest heavily in custom exploits and malware targeting critical edge infrastructure globally.
Their activities align with broader strategies observed among similar groups aiming to compromise sensitive systems across various industries.
Ivanti has released patches addressing CVE-2025-22457 in ICS version 22.7R2.6 or later.
Organizations are urged to upgrade their systems immediately and follow guidance provided in Ivanti’s Security Advisory.
Additional measures include using Integrity Checker Tools (ICT) to detect anomalies, investigating core dumps related to web processes, and monitoring TLS certificates presented to appliances for irregularities.
This incident serves as a stark reminder for organizations to prioritize securing edge devices against increasingly sophisticated cyber threats.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates
