Sila Ozeren Hacioglu. (2025, May 5). UNC5221’s Latest Exploit: Weaponizing CVE-2025-22457 in Ivanti Connect Secure. Retrieved April 13, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has extracted the device’s Linux kernel image (vmlinux). |
| T1027.013 Encrypted/Encoded File |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has encoded a private key with XOR. SPAWNCHIMERA has also encrypted data to be extracted using AES encryption. |
| T1027.013 Encrypted/Encoded File |
MalwareDRYHOOK | DRYHOOK has encrypted stolen credentials strings within a file using both Base64 and RC4 with a hard-coded key. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
MalwareBRUSHFIRE | BRUSHFIRE has the ability to exfiltrate data on-demand through executing commands obtained via monitoring for specially crafted packets and sending output back in an embedded SSL response. |
| T1055.012 Process Hollowing |
MalwareTRAILBLAZE | TRAILBLAZE has injected a hook into an existing process to load BRUSHFIRE in the spaces allocated memory to include the Ivanti Connect Secure (ICS) web process named `web`. |
| T1056.001 Keylogging |
MalwareDRYHOOK | DRYHOOK has captured user credentials and passwords in plaintext and has encrypted them in a stored file on the network device. |
| T1057 Process Discovery |
MalwareTRAILBLAZE | TRAILBLAZE has conducted process discovery by searching for specific named processes such as `/home/bin/web`. |
| T1059.006 Python |
MalwareDRYHOOK | DRYHOOK is a Python-based script that executes within the victim environment. |
| T1059.008 Network Device CLI |
MalwareDRYHOOK | DRYHOOK has the ability to interact with Ivanti Connect Secure environments and to modify system components. |
| T1070.004 File Deletion |
MalwareTRAILBLAZE | TRAILBLAZE has the ability to delete temporary files and contents in specified directories to cover its tracks. |
| T1074.001 Local Data Staging |
MalwareDRYHOOK | DRYHOOK has stored stolen credentials for future use in the temp folder of a victimized Ivanti Connect Secure VPN device, specifically in the file location `/tmp/cmmmap.kumMW`. |
| T1106 Native API |
MalwareTRAILBLAZE | TRAILBLAZE has leveraged raw syscalls to execute commands. |
| T1205 Traffic Signaling |
MalwareBRUSHFIRE | BRUSHFIRE has monitored inbound VPN traffic to compromised appliances until specific inbound packets contain a specific magic string/pattern instead of external beaconing. |
| T1222.002 Linux and Mac Permissions |
MalwareDRYHOOK | DRYHOOK has the ability to remount the filesystem as “read-write” to make changes and then restores it to “read-only” prior to killing processes to apply the modifications. |
| T1556 Modify Authentication Process |
MalwareDRYHOOK | DRYHOOK has intercepted and logged user credentials by modifying the Perl module in Ivanti Connect Secure VPN edge-devices located within `/home/perl/DSAuth.pm`. |
| T1601 Modify System Image |
MalwareDRYHOOK | DRYHOOK has modified the Ivanti Connect Secure VPN authentication Perl module `DSAuth.pm` by reading its contents in the buffer, then finding and replacing select lines of code. |
| T1620 Reflective Code Loading |
MalwareBRUSHFIRE | BRUSHFIRE has executed its commands within memory and is not saved on disk. |
| T1685 Disable or Modify Tools |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has modified the Ivanti Integrity Checker Tool to evade detection. |
| T1690 Prevent Command History Logging |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has disabled logging and log forwarding on Ivanti devices targeting the `dslogserver` process. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.