Malware.View on attack.mitre.org
TRAILBLAZE is an in-memory dropper used to deploy the passive backdoor BRUSHFIRE. First reported in March 2025, TRAILBLAZE has been observed in operations attributed to People's Republic of China (PRC) state-sponsored affiliated actors, including UNC5221 and SYLVANITE.
| Technique | Procedure example |
|---|---|
| T1055.012 Process Hollowing |
TRAILBLAZE has injected a hook into an existing process to load BRUSHFIRE in the spaces allocated memory to include the Ivanti Connect Secure (ICS) web process named `web`. |
| T1057 Process Discovery |
TRAILBLAZE has conducted process discovery by searching for specific named processes such as `/home/bin/web`. |
| T1070.004 File Deletion |
TRAILBLAZE has the ability to delete temporary files and contents in specified directories to cover its tracks. |
| T1106 Native API |
TRAILBLAZE has leveraged raw syscalls to execute commands. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.