What Happened
Ivanti disclosed CVE-2025-22457, a critical (CVSS 9.0) stack-based buffer overflow affecting Connect Secure, Policy Secure, and ZTA Gateways. Mandiant confirmed active exploitation by UNC5221, a China-nexus threat actor previously linked to Volt Typhoon operations.
Malware Deployed
- TRAILBLAZE: In-memory dropper executing via shell script
- BRUSHFIRE: Passive backdoor with encrypted C2 communication injected into running processes
- SPAWN: Malware ecosystem (SPAWNANT, SPAWNMOLE, SPAWNSNAIL) for persistence
Exploitation Window
Mandiant observed exploitation beginning in mid-March 2025, approximately three weeks before the April 3rd disclosure. The vulnerability was initially introduced when Ivanti tried to fix an earlier bug (CVE-2025-0282) in Connect Secure 22.7R2.5 — the patch was incomplete.
Recommended Actions
- Run the Ivanti Integrity Checker Tool (ICT) before and after patching
- Factory reset compromised appliances — do not trust software-only remediation
- Rotate all credentials accessible via the VPN gateway
- Review CISA Advisory AA25-093A for detailed IOCs
- Enable external authentication logging and audit auth events