Target Industry

Threat actor UNC5221 targets defence, telecommunications, financial services, aerospace, and technology.

Overview

A critical vulnerability has been discovered in Ivanti Connect Secure VPN appliances. This vulnerability, tracked as CVE-2025-22457 (CVSS Score 9), was initially assessed as low risk but has since been upgraded to critical. It is a stack-based buffer overflow that allows remote, unauthenticated attackers to execute code on the target device. Ivanti has released patches and urges immediate upgrades. It is currently believed that a suspected China-nexus threat actor (UNC5221) is actively exploiting it in the wild. 

Impact

The vulnerability allows remote, unauthenticated threat actors to execute arbitrary code on the target device. Exploiting this flaw could enable threat actors to move laterally within a network, compromising additional systems and data. The vulnerability can be used to deploy malware, including ransomware, which can disrupt operations and demand ransom payments.  

Affected Products

  • Ivanti Connect Secure: Versions prior to 9.1R15 
  • Ivanti Policy Secure: Versions prior to 9.1R15 
  • Ivanti ZTA Gateway: Versions prior to 9.1R15 

Exploitation

CVE-2025-22457 is exploited through a stack-based buffer overflow. Threat actors remotely send specially and unauthenticated crafted packets to the target device, causing the overflow. This allows them to execute arbitrary code, gain control over the device, and deploy malware These actions can lead to unauthorised access to sensitive data, network compromise, and persistent malicious activities 

UNC5221 is using this vulnerability to deploy two new malware families, Trailblaze and Brushfire, along with other tools. Trailblaze, is an in-memory dropper that executes malicious payloads directly within the memory of a running process. Brushfire is a passive backdoor that is injected into the memory of a running web process. It allows threat actors to maintain persistent access to the compromised device. 

Containment, Mitigations & Remediations

To mitigate against this vulnerability for Ivanti Connect Secure it is highly recommended to update to the latest version. However, patches for Ivanti Policy Secure and ZTA Gateways will not be available until later in April 2025. 

Further steps for mitigating against this vulnerability in Ivanti Connect Secure VPN appliances are: 

  • Monitor Network Traffic: Implement network monitoring to detect any unusual or suspicious activity that could indicate an attempted exploitation 
  • Restrict Access: Limit access to the VPN appliances to trusted IP addresses and use strong authentication methods to reduce the risk of unauthorised access 
  • Regular Audits: Conduct regular security audits and vulnerability assessments to identify and address potential weaknesses in the network. 

Threat Landscape

Ivanti’s products, including Connect Secure appliances, are widely deployed in enterprise environments across various sectors, including government, healthcare, financial services, energy, and education. These solutions enable secure remote access and support for zero-trust access frameworks, making them high-value targets for cyber attackers. 

Threat Group

UNC5221 is a threat group known to exploit zero-day vulnerabilities in Ivanti products. A suspected China-nexus espionage group, UNC5221 was first identified in December 2023. It was observed exploiting vulnerabilities in Ivanti Connect Secure VPN appliances, including CVE-2023-46805 and CVE-2024-21887. 

UNC5221 is also associated with RESURGE, SPAWNCHIMERA, SPAWNSNAIL, SpawnAnt, and SpawnSloth malware families. The group is also known as Red Dev 61 or UTA0178, primarily targeting the US. 

Further Information

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content