Full Report
Mandiant warned that Chinese espionage actor UNC5221 is actively exploiting a critical Ivanti vulnerability, which can lead to remote code execution
Analysis Summary
# Main Topic
Active exploitation of the critical Ivanti vulnerability, tracked as **CVE-2025-22457**, by the Chinese espionage actor **UNC5221**, aimed at achieving Remote Code Execution (RCE) on Ivanti Connect Secure (ICS) appliances.
## Key Points
- The vulnerability is a **buffer overflow** flaw that received a critical CVSS score of **9.0**.
- Although initially suspected to be a low-risk Denial of Service (DoS) vulnerability due to limited character space, UNC5221 successfully developed an exploit to achieve **Remote Code Execution (RCE)** against versions 22.7R2.5 and earlier.
- Active exploitation in the wild has been observed since **mid-March 2025**.
- The exploitation is followed by significant post-compromise activity, including the deployment of novel, memory-resident malware families designed to evade detection.
## Threat Actors
- **Attribution:** Suspected Chinese state threat actor.
- **Designation:** **UNC5221**.
- **Motivation:** Espionage, evidenced by their history of targeting edge devices for broad access.
- **History:** Previously observed exploiting zero-day vulnerabilities in other Ivanti products, as well as flaws affecting NetScaler ADC and NetScaler Gateway appliances.
## TTPs
- **Initial Access:** Exploitation of **CVE-2025-22457** (Buffer Overflow leading to RCE).
- **Post-Compromise Payload:** Deployment of two newly identified, **memory-resident** malware families for stealth.
- **Trailblaze:** A minimal in-dropper used to inject the main backdoor.
- **Brushfire:** A passive backdoor that hooks SSL functions to receive commands.
- **Spawn Family Malware:** Including **Spawnsloth** (log tampering targeting `dslogserver` to disable local/remote logging), **Spawnsnare** (Linux kernel image extraction and AES encryption utility), and **Spawnwave** (an evolved version of Spawnant).
- **Goal:** Establish persistent backdoor access, enabling credential theft, further network intrusion, and data exfiltration.
## Affected Systems
- **Product:** Ivanti Connect Secure (ICS).
- **Affected Versions (Pre-Patch):** Versions **22.7R2.5 and earlier**.
- **Affected Component:** The specific product running the flawed software.
- **Scope:** Broad targeting of organizations globally, consistent with espionage groups focusing on **edge devices**.
## Mitigations
- **Patch Deployment:** All ISC customers using versions 22.7R2.6 and lower are urged to **apply the previously released patches** immediately.
- **Patch Availability:** A patch for CVE-2025-22457 was released on **February 11, 2025**, in ICS version **22.7R2.6**.
- **Detection:** Organizations must enhance detection capabilities specifically for memory-resident malware, as standard EDR solutions may struggle due to the nature of these custom implants.
## Conclusion
UNC5221 is aggressively leveraging a critical Ivanti flaw to gain persistent, stealthy access to enterprise networks via edge devices. The use of memory-resident malware signifies a sophisticated espionage campaign. Immediate patching to version 22.7R2.6 or higher is critical, alongside heightened monitoring for post-exploitation activity associated with the documented malware families.