Target Industry
Threat actor UNC5221 targets defence, telecommunications, financial services, aerospace, and technology.
Overview
A critical vulnerability has been discovered in Ivanti Connect Secure VPN appliances. This vulnerability, tracked as CVE-2025-22457 (CVSS Score 9), was initially assessed as low risk but has since been upgraded to critical. It is a stack-based buffer overflow that allows remote, unauthenticated attackers to execute code on the target device. Ivanti has released patches and urges immediate upgrades. It is currently believed that a suspected China-nexus threat actor (UNC5221) is actively exploiting it in the wild.
Impact
The vulnerability allows remote, unauthenticated threat actors to execute arbitrary code on the target device. Exploiting this flaw could enable threat actors to move laterally within a network, compromising additional systems and data. The vulnerability can be used to deploy malware, including ransomware, which can disrupt operations and demand ransom payments.
Affected Products
- Ivanti Connect Secure: Versions prior to 9.1R15
- Ivanti Policy Secure: Versions prior to 9.1R15
- Ivanti ZTA Gateway: Versions prior to 9.1R15
Exploitation
CVE-2025-22457 is exploited through a stack-based buffer overflow. Threat actors remotely send specially and unauthenticated crafted packets to the target device, causing the overflow. This allows them to execute arbitrary code, gain control over the device, and deploy malware These actions can lead to unauthorised access to sensitive data, network compromise, and persistent malicious activities
UNC5221 is using this vulnerability to deploy two new malware families, Trailblaze and Brushfire, along with other tools. Trailblaze, is an in-memory dropper that executes malicious payloads directly within the memory of a running process. Brushfire is a passive backdoor that is injected into the memory of a running web process. It allows threat actors to maintain persistent access to the compromised device.
Containment, Mitigations & Remediations
To mitigate against this vulnerability for Ivanti Connect Secure it is highly recommended to update to the latest version. However, patches for Ivanti Policy Secure and ZTA Gateways will not be available until later in April 2025.
Further steps for mitigating against this vulnerability in Ivanti Connect Secure VPN appliances are:
- Monitor Network Traffic: Implement network monitoring to detect any unusual or suspicious activity that could indicate an attempted exploitation
- Restrict Access: Limit access to the VPN appliances to trusted IP addresses and use strong authentication methods to reduce the risk of unauthorised access
- Regular Audits: Conduct regular security audits and vulnerability assessments to identify and address potential weaknesses in the network.
Threat Landscape
Ivanti’s products, including Connect Secure appliances, are widely deployed in enterprise environments across various sectors, including government, healthcare, financial services, energy, and education. These solutions enable secure remote access and support for zero-trust access frameworks, making them high-value targets for cyber attackers.
Threat Group
UNC5221 is a threat group known to exploit zero-day vulnerabilities in Ivanti products. A suspected China-nexus espionage group, UNC5221 was first identified in December 2023. It was observed exploiting vulnerabilities in Ivanti Connect Secure VPN appliances, including CVE-2023-46805 and CVE-2024-21887.
UNC5221 is also associated with RESURGE, SPAWNCHIMERA, SPAWNSNAIL, SpawnAnt, and SpawnSloth malware families. The group is also known as Red Dev 61 or UTA0178, primarily targeting the US.
Further Information













