ATT&CKReferencesGoogle UNC5221 Ivanti April 2025

Google UNC5221 Ivanti April 2025

John Wolfram, Michael Edie, Jacob Thompson, Matt Lin, Josh Murchie. (2025, April 3). Suspected China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457). Retrieved April 13, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software3

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareSPAWNCHIMERA

SPAWNCHIMERA has extracted the device’s Linux kernel image (vmlinux).

T1027.013
Encrypted/Encoded File
MalwareSPAWNCHIMERA

SPAWNCHIMERA has encoded a private key with XOR. SPAWNCHIMERA has also encrypted data to be extracted using AES encryption.

T1055.012
Process Hollowing
MalwareTRAILBLAZE

TRAILBLAZE has injected a hook into an existing process to load BRUSHFIRE in the spaces allocated memory to include the Ivanti Connect Secure (ICS) web process named `web`.

T1057
Process Discovery
MalwareTRAILBLAZE

TRAILBLAZE has conducted process discovery by searching for specific named processes such as `/home/bin/web`.

T1070.004
File Deletion
MalwareTRAILBLAZE

TRAILBLAZE has the ability to delete temporary files and contents in specified directories to cover its tracks.

T1106
Native API
MalwareTRAILBLAZE

TRAILBLAZE has leveraged raw syscalls to execute commands.

T1140
Deobfuscate/Decode Files or Information
MalwareBRUSHFIRE

BRUSHFIRE has decrypted XOR strings prior to execution.

T1620
Reflective Code Loading
MalwareBRUSHFIRE

BRUSHFIRE has executed its commands within memory and is not saved on disk.

T1690
Prevent Command History Logging
MalwareSPAWNCHIMERA

SPAWNCHIMERA has disabled logging and log forwarding on Ivanti devices targeting the `dslogserver` process.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.