216.73.216.6

China-Nexus Threat Actor Actively Exploiting Ivanti Endpoint Manager Mobile (CVE-2025-4428) Vulnerability

· Published 21/05/2025 23:03 · Modified 22/05/2025 09:50

Export JSON

Essential information

Published
21/05/2025 23:03
Modified
22/05/2025 09:50
Tags
2025-05-21 CVE-2025-4427 CVE-2025-4428 auto-color china-nexus data exfiltration epmm frp ivanti krustyloader sliver unauthenticated rce
Related entities
4 vulnerabilities (cve), 12 observables, 1 intrusion sets (apt), 19 techniques (mitre), 3 malware, 9 others

Description

A critical vulnerability in Endpoint Manager Mobile () is being actively exploited by a threat actor, UNC5221. The exploitation targets internet-facing deployments across various sectors including healthcare, telecommunications, and government. The attackers utilize unauthenticated remote code execution to gain initial access, followed by the deployment of malware for persistence. They leverage hardcoded MySQL credentials to exfiltrate sensitive data from the database. The threat actor also uses the Fast Reverse Proxy () tool for network reconnaissance and lateral movement. The compromised systems span multiple countries in Europe, North America, and Asia-Pacific, indicating a global espionage campaign likely aligned with Chinese state interests.

External references