BRUSHFIRE

S9011

Malware.View on attack.mitre.org

About this malware

BRUSHFIRE is a passive backdoor written in C that executes in-memory within an existing process. First reported in March 2025, BRUSHFIRE has been observed in activity attributed to People's Republic of China (PRC) state-affiliated threat actors, including UNC5221 and SYLVANITE.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol

BRUSHFIRE has the ability to exfiltrate data on-demand through executing commands obtained via monitoring for specially crafted packets and sending output back in an embedded SSL response.

T1140
Deobfuscate/Decode Files or Information

BRUSHFIRE has decrypted XOR strings prior to execution.

T1205
Traffic Signaling

BRUSHFIRE has monitored inbound VPN traffic to compromised appliances until specific inbound packets contain a specific magic string/pattern instead of external beaconing.

T1620
Reflective Code Loading

BRUSHFIRE has executed its commands within memory and is not saved on disk.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References3

  1. Dragos SYLVANITE MuddyWater Electrum March 2026 Open source
    Dragos. (2026, March 24). Dragos 2026 OT Cybersecurity Report: Year in Review, O&G and Petrochemicals Focus. Retrieved April 17, 2026.
  2. Google UNC5221 Ivanti April 2025 Open source
    John Wolfram, Michael Edie, Jacob Thompson, Matt Lin, Josh Murchie. (2025, April 3). Suspected China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457). Retrieved April 13, 2026.
  3. Picus Security UNC5221 Ivanti May 2025 Open source
    Sila Ozeren Hacioglu. (2025, May 5). UNC5221’s Latest Exploit: Weaponizing CVE-2025-22457 in Ivanti Connect Secure. Retrieved April 13, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.