ATT&CKSoftwareTRAILBLAZE

TRAILBLAZE

S9012

Malware.View on attack.mitre.org

About this malware

TRAILBLAZE is an in-memory dropper used to deploy the passive backdoor BRUSHFIRE. First reported in March 2025, TRAILBLAZE has been observed in operations attributed to People's Republic of China (PRC) state-sponsored affiliated actors, including UNC5221 and SYLVANITE.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1055.012
Process Hollowing

TRAILBLAZE has injected a hook into an existing process to load BRUSHFIRE in the spaces allocated memory to include the Ivanti Connect Secure (ICS) web process named `web`.

T1057
Process Discovery

TRAILBLAZE has conducted process discovery by searching for specific named processes such as `/home/bin/web`.

T1070.004
File Deletion

TRAILBLAZE has the ability to delete temporary files and contents in specified directories to cover its tracks.

T1106
Native API

TRAILBLAZE has leveraged raw syscalls to execute commands.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References3

  1. Dragos SYLVANITE MuddyWater Electrum March 2026 Open source
    Dragos. (2026, March 24). Dragos 2026 OT Cybersecurity Report: Year in Review, O&G and Petrochemicals Focus. Retrieved April 17, 2026.
  2. Google UNC5221 Ivanti April 2025 Open source
    John Wolfram, Michael Edie, Jacob Thompson, Matt Lin, Josh Murchie. (2025, April 3). Suspected China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457). Retrieved April 13, 2026.
  3. Picus Security UNC5221 Ivanti May 2025 Open source
    Sila Ozeren Hacioglu. (2025, May 5). UNC5221’s Latest Exploit: Weaponizing CVE-2025-22457 in Ivanti Connect Secure. Retrieved April 13, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.