A suspected China-linked espionage actor has been actively exploiting CVE-2025-22457, a critical stack-based/buffer overflow flaw in Ivanti Connect Secure that enables unauthenticated remote code execution and full device compromise. Ivanti and Mandiant said exploitation began in mid-March against vulnerable Ivanti Connect Secure appliances, with attacks also affecting Pulse Connect Secure and prompting security updates for Ivanti Policy Secure and ZTA Gateways. The flaw carries a CVSS 9.0 rating and affects Ivanti Connect Secure 22.7R2.5 and earlier, while the corrected version was shipped in 22.7R2.6.
Mandiant attributed the activity and deployment of the SPAWN malware ecosystem to UNC5221, a suspected China-nexus threat actor known for targeting edge devices with zero-days. Post-compromise activity included a shell-script dropper that installs two newly identified malware families, TRAILBLAZE and BRUSHFIRE, while operators also attempted to evade detection by tampering with Ivanti's Integrity Checker Tool and routing activity through compromised Cyberoam, QNAP, and ASUS devices. Ivanti and defenders urged organizations to immediately upgrade supported systems, migrate away from end-of-support Pulse Connect Secure, and monitor for indicators such as web-process core dumps, Integrity Checker Tool state dumps, and anomalous client TLS certificates.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Ivanti released security updates for Ivanti Connect Secure, Ivanti Policy Secure, and ZTA Gateways to address CVE-2025-22457. The advisory also said attacks had targeted Ivanti Connect Secure and the end-of-support Pulse Connect Secure product.
Mandiant and Ivanti observed active exploitation of CVE-2025-22457 beginning in mid-March 2025 against Ivanti Connect Secure appliances. The activity was later linked to post-exploitation malware deployment including TRAILBLAZE, BRUSHFIRE, and the SPAWN ecosystem.
Google Threat Intelligence Group assessed that UNC5221, a suspected China-nexus espionage actor, was responsible for exploiting CVE-2025-22457 and deploying SPAWN malware on affected edge devices. The report also described evasion tactics including tampering with Ivanti's Integrity Checker Tool and use of an obfuscation network of compromised devices.
Ivanti publicly disclosed CVE-2025-22457, a critical buffer overflow vulnerability affecting Ivanti Connect Secure, on April 3, 2025. The disclosure noted active exploitation, and guidance was issued to upgrade supported products immediately.
Ivanti Connect Secure version 22.7R2.6 was released with a fix for CVE-2025-22457 before the flaw was publicly disclosed. The issue was initially assessed as a low-risk denial-of-service condition rather than remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.