What Happened

Ivanti disclosed CVE-2025-22457, a critical (CVSS 9.0) stack-based buffer overflow affecting Connect Secure, Policy Secure, and ZTA Gateways. Mandiant confirmed active exploitation by UNC5221, a China-nexus threat actor previously linked to Volt Typhoon operations.

Malware Deployed

  • TRAILBLAZE: In-memory dropper executing via shell script
  • BRUSHFIRE: Passive backdoor with encrypted C2 communication injected into running processes
  • SPAWN: Malware ecosystem (SPAWNANT, SPAWNMOLE, SPAWNSNAIL) for persistence

Exploitation Window

Mandiant observed exploitation beginning in mid-March 2025, approximately three weeks before the April 3rd disclosure. The vulnerability was initially introduced when Ivanti tried to fix an earlier bug (CVE-2025-0282) in Connect Secure 22.7R2.5 — the patch was incomplete.

Recommended Actions

Upgrade to Connect Secure 22.7R2.6 or later immediately.
  1. Run the Ivanti Integrity Checker Tool (ICT) before and after patching
  2. Factory reset compromised appliances — do not trust software-only remediation
  3. Rotate all credentials accessible via the VPN gateway
  4. Review CISA Advisory AA25-093A for detailed IOCs
  5. Enable external authentication logging and audit auth events