An authentication-bypass vulnerability in Ivanti Endpoint Manager Mobile (EPMM), CVE-2025-4427, enables unauthenticated remote code execution when chained with CVE-2025-4428. Ivanti released fixes on May 13, 2025, and reported exploitation beginning May 15, including intrusions attributed to a China-nexus espionage group. WatchTowr Labs documented the unauthenticated RCE chain, while Wiz reported its exploitation in the wild.
CrowdSec recorded 3,978 matching signals between June 24 and September 20, 2026, including two large scanning sweeps amid otherwise lower-volume activity. These signals represent vulnerability scans and exploitation attempts—not confirmed compromises or a census of EPMM deployments. Organizations should upgrade to a current supported release, restrict external access to administrative APIs, and investigate previously exposed servers for persistence and stolen credentials; patching alone does not remove an existing compromise.

See which actors are running it and whether you're in range.
14 events from the most recent confirmed update back to the earliest known activity.
The Live Exploit Tracker returned the activity classification to Background Noise after its September 13 escalation.
CrowdSec's Live Exploit Tracker changed the activity classification to Active Exploitation. Its telemetry does not independently confirm successful exploitation.
CrowdSec recorded 371 distinct sources and 556 matching signals on September 11, the peak of its June–September observation window. More than 90% of signals originated from US addresses, and most targets were in Germany.
CrowdSec observed 258 distinct sources on August 26, compared with a typical daily level of approximately 11. More than 90% of signals in this sweep originated from US addresses, with most targets in Germany.
CrowdSec observed 17 source addresses generating 271 matching signals on July 9, 2026. Of those signals, 164 were directed at Austria.
CrowdSec recorded its first matching traffic one day after activating the rule. Matching requests can represent vulnerability probes or exploitation attempts and do not establish successful compromise.
CrowdSec activated a detection rule for traffic associated with the EPMM vulnerability.
CISA added CVE-2025-4427 and CVE-2025-4428 to its Known Exploited Vulnerabilities catalog.
EclecticIQ traced in-the-wild intrusions attributed to a China-nexus espionage group to May 15, 2025. The reported campaign affected healthcare, telecommunications, local government, and aviation organizations across Europe, North America, and Asia-Pacific, with attackers stealing device information and enterprise credentials.
watchTowr Labs published a working exploit chaining CVE-2025-4427 and CVE-2025-4428. Researchers Sonny and Piotr Bazydło analyzed how pre-authentication parameter validation and expression evaluation enable remote command execution.
On May 13, 2025, Ivanti disclosed CVE-2025-4427 and released EPMM fixes in versions 11.12.0.5, 12.3.0.2, 12.4.0.2, and 12.5.0.1. Chaining the authentication bypass with CVE-2025-4428 enables unauthenticated remote code execution.
During multiple incident-response engagements in May 2025, Profero identified an unnamed threat group deploying KrustyLoader on compromised EPMM appliances, with successful executions producing Sliver command-and-control beacons. Investigations also found attackers had moved laterally and established persistence before appliances were isolated.
Wiz and EclecticIQ documented web shells under /mi/tomcat/webapps/mifs/, Sliver implants, database dumps, and dumped LDAP tables in compromised EPMM environments.
ProjectDiscovery released a detection template during the same week as watchTowr's May 15, 2025 exploit publication. The source does not provide a specific release day.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
crowdsec.net
Open sourceprofero.io
Open sourcewiz.io
Open sourcelabs.watchtowr.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.