216.73.217.80

Suspected China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457)

· Published 04/04/2025 07:07 · Modified 04/04/2025 17:02

Export JSON

Essential information

Published
04/04/2025 07:07
Modified
04/04/2025 17:02
Tags
2025-04-04 CVE-2025-22457 brushfire buffer overflow china-nexus edge devices espionage ivanti connect secure remote code execution spawnsloth spawnsnare spawnwave trailblaze vpn zero-day
Related entities
1 intrusion sets (apt), 19 techniques (mitre), 5 malware

Description

A critical security vulnerability, , affecting appliances has been actively exploited since mid-March 2025. The vulnerability allows through a . Two new malware families, and , have been deployed along with the previously known SPAWN ecosystem. The suspected actor UNC5221 is believed to be behind the attacks. Post-exploitation activities include the use of a shell script dropper, deployment of various malware components, and attempts to evade detection by modifying the Integrity Checker Tool. Organizations are urged to immediately patch their systems and monitor for suspicious activity.

External references