John Wolfram, Michael Edie, Jacob Thompson, Matt Lin, Josh Murchie. (2025, April 3). Suspected China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457). Retrieved April 13, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has extracted the device’s Linux kernel image (vmlinux). |
| T1027.013 Encrypted/Encoded File |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has encoded a private key with XOR. SPAWNCHIMERA has also encrypted data to be extracted using AES encryption. |
| T1055.012 Process Hollowing |
MalwareTRAILBLAZE | TRAILBLAZE has injected a hook into an existing process to load BRUSHFIRE in the spaces allocated memory to include the Ivanti Connect Secure (ICS) web process named `web`. |
| T1057 Process Discovery |
MalwareTRAILBLAZE | TRAILBLAZE has conducted process discovery by searching for specific named processes such as `/home/bin/web`. |
| T1070.004 File Deletion |
MalwareTRAILBLAZE | TRAILBLAZE has the ability to delete temporary files and contents in specified directories to cover its tracks. |
| T1106 Native API |
MalwareTRAILBLAZE | TRAILBLAZE has leveraged raw syscalls to execute commands. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBRUSHFIRE | BRUSHFIRE has decrypted XOR strings prior to execution. |
| T1620 Reflective Code Loading |
MalwareBRUSHFIRE | BRUSHFIRE has executed its commands within memory and is not saved on disk. |
| T1690 Prevent Command History Logging |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has disabled logging and log forwarding on Ivanti devices targeting the `dslogserver` process. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.