ATT&CKReferencesPicus Security UNC5221 Ivanti May 2025

Picus Security UNC5221 Ivanti May 2025

Sila Ozeren Hacioglu. (2025, May 5). UNC5221’s Latest Exploit: Weaponizing CVE-2025-22457 in Ivanti Connect Secure. Retrieved April 13, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software4

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareSPAWNCHIMERA

SPAWNCHIMERA has extracted the device’s Linux kernel image (vmlinux).

T1027.013
Encrypted/Encoded File
MalwareSPAWNCHIMERA

SPAWNCHIMERA has encoded a private key with XOR. SPAWNCHIMERA has also encrypted data to be extracted using AES encryption.

T1027.013
Encrypted/Encoded File
MalwareDRYHOOK

DRYHOOK has encrypted stolen credentials strings within a file using both Base64 and RC4 with a hard-coded key.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
MalwareBRUSHFIRE

BRUSHFIRE has the ability to exfiltrate data on-demand through executing commands obtained via monitoring for specially crafted packets and sending output back in an embedded SSL response.

T1055.012
Process Hollowing
MalwareTRAILBLAZE

TRAILBLAZE has injected a hook into an existing process to load BRUSHFIRE in the spaces allocated memory to include the Ivanti Connect Secure (ICS) web process named `web`.

T1056.001
Keylogging
MalwareDRYHOOK

DRYHOOK has captured user credentials and passwords in plaintext and has encrypted them in a stored file on the network device.

T1057
Process Discovery
MalwareTRAILBLAZE

TRAILBLAZE has conducted process discovery by searching for specific named processes such as `/home/bin/web`.

T1059.006
Python
MalwareDRYHOOK

DRYHOOK is a Python-based script that executes within the victim environment.

T1059.008
Network Device CLI
MalwareDRYHOOK

DRYHOOK has the ability to interact with Ivanti Connect Secure environments and to modify system components.

T1070.004
File Deletion
MalwareTRAILBLAZE

TRAILBLAZE has the ability to delete temporary files and contents in specified directories to cover its tracks.

T1074.001
Local Data Staging
MalwareDRYHOOK

DRYHOOK has stored stolen credentials for future use in the temp folder of a victimized Ivanti Connect Secure VPN device, specifically in the file location `/tmp/cmmmap.kumMW`.

T1106
Native API
MalwareTRAILBLAZE

TRAILBLAZE has leveraged raw syscalls to execute commands.

T1205
Traffic Signaling
MalwareBRUSHFIRE

BRUSHFIRE has monitored inbound VPN traffic to compromised appliances until specific inbound packets contain a specific magic string/pattern instead of external beaconing.

T1222.002
Linux and Mac Permissions
MalwareDRYHOOK

DRYHOOK has the ability to remount the filesystem as “read-write” to make changes and then restores it to “read-only” prior to killing processes to apply the modifications.

T1556
Modify Authentication Process
MalwareDRYHOOK

DRYHOOK has intercepted and logged user credentials by modifying the Perl module in Ivanti Connect Secure VPN edge-devices located within `/home/perl/DSAuth.pm`.

T1601
Modify System Image
MalwareDRYHOOK

DRYHOOK has modified the Ivanti Connect Secure VPN authentication Perl module `DSAuth.pm` by reading its contents in the buffer, then finding and replacing select lines of code.

T1620
Reflective Code Loading
MalwareBRUSHFIRE

BRUSHFIRE has executed its commands within memory and is not saved on disk.

T1685
Disable or Modify Tools
MalwareSPAWNCHIMERA

SPAWNCHIMERA has modified the Ivanti Integrity Checker Tool to evade detection.

T1690
Prevent Command History Logging
MalwareSPAWNCHIMERA

SPAWNCHIMERA has disabled logging and log forwarding on Ivanti devices targeting the `dslogserver` process.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.