{"id":3054,"date":"2025-04-04T10:03:37","date_gmt":"2025-04-04T10:03:37","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/04\/04\/chinese-hackers-actively-exploiting-ivanti-vpn-vulnerability-to-deploy-malware\/"},"modified":"2025-04-04T10:03:37","modified_gmt":"2025-04-04T10:03:37","slug":"chinese-hackers-actively-exploiting-ivanti-vpn-vulnerability-to-deploy-malware","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/04\/04\/chinese-hackers-actively-exploiting-ivanti-vpn-vulnerability-to-deploy-malware\/","title":{"rendered":"Chinese Hackers Actively Exploiting Ivanti VPN Vulnerability to Deploy Malware"},"content":{"rendered":"<p>    Chinese Hackers Actively Exploiting Ivanti VPN Vulnerability to Deploy Malware<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Security researchers have identified a critical vulnerability in Ivanti Connect Secure (ICS) VPN appliances that is being actively exploited by suspected Chinese threat actors.<\/p>\n<p>The vulnerability, tracked as CVE-2025-22457, is a buffer overflow flaw affecting ICS version 22.7R2.5 and earlier that can lead to remote code execution.<\/p>\n<p>Evidence suggests exploitation began in mid-March 2025, with attackers leveraging the vulnerability to deploy sophisticated malware strains designed for espionage operations.<\/p>\n<p>The attacks have been attributed to UNC5221, a suspected China-nexus espionage actor with a history of targeting edge devices through zero-day exploitations dating back to 2023.<\/p>\n<p>This group has demonstrated sophisticated capabilities, including the ability to reverse-engineer security patches to develop working exploits.<\/p>\n<p>In this campaign, they likely studied the February 2025 patch for ICS 22.7R2.6 to develop their attack methodology.<\/p>\n<p>Google Threat Intelligence analysts <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/china-nexus-exploiting-critical-ivanti-vulnerability\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> that following successful exploitation, the threat actors deploy multiple malware families, including two newly discovered tools \u2013 TRAILBLAZE and BRUSHFIRE \u2013 alongside their previously documented SPAWN ecosystem of malware.<\/p>\n<p>These tools work in concert to establish persistent access while evading detection mechanisms.<\/p>\n<p>The vulnerability\u2019s exploitation represents a concerning evolution in UNC5221\u2019s tactics, as they transition from exclusively using <a href=\"https:\/\/cybersecuritynews.com\/microsoft-security-updates-5-zero-days\/\" target=\"_blank\" rel=\"noreferrer noopener\">zero-day vulnerabilities<\/a> to also leveraging n-day flaws in their arsenal. <\/p>\n<p>According to security researchers, the group targets a wide range of countries and vertical sectors, demonstrating an aggressive operational tempo and extensive toolset.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Post-Exploitation Tactics<\/strong><\/h2>\n<p>After successfully exploiting the vulnerability, attackers deploy a sophisticated attack chain starting with a shell script dropper.<\/p>\n<p>This initial script executes TRAILBLAZE, an in-memory dropper written in bare C using raw syscalls, designed to be minimal and stealthy.<\/p>\n<p>TRAILBLAZE then injects the BRUSHFIRE passive <a href=\"https:\/\/cybersecuritynews.com\/researchers-hijacked-4000-backdoors\/\" target=\"_blank\" rel=\"noreferrer noopener\">backdoor<\/a> into a running <code>\/home\/bin\/web<\/code> process.<\/p>\n<p>The infection process creates several temporary files that store information about the target process, including:-<\/p>\n<pre class=\"wp-block-code\"><code>\/tmp\/.p: contains the PID of the \/home\/bin\/web process\n\/tmp\/.m: contains a memory map of that process\n\/tmp\/.w: contains the base address of the web binary\n\/tmp\/.s: contains the base address of libssl.so\n\/tmp\/.r: contains the BRUSHFIRE passive backdoor\n\/tmp\/.i: contains the TRAILBLAZE dropper<\/code><\/pre>\n<p>BRUSHFIRE operates by hooking the SSL_read function, allowing it to intercept encrypted communications.<\/p>\n<p>When specific trigger strings are detected, it decrypts and executes shellcode contained in the intercepted data, sending results back through SSL_write.<\/p>\n<p>This sophisticated technique enables attackers to maintain a persistent presence while minimizing detection risk, as they operate entirely in memory without writing malicious files to disk.<\/p>\n<p>Security experts recommend organizations immediately upgrade affected <a href=\"https:\/\/cybersecuritynews.com\/ivanti-vpn-zero-day-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Ivanti<\/a> Connect Secure appliances to version 22.7R2.6 or later and utilize the Integrity Checker Tool to identify any suspicious activity.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><code><strong><code>Investigate Real-World Malicious Links &amp; Phishing Attacks With\u00a0<strong>Threat Intelligence Lookup<\/strong>\u00a0-\u00a0<a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=3-techniques-to-improve-th&amp;utm_content=plans&amp;utm_term=010425\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try 50 Request for Free<\/a><\/code><\/strong><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/chinese-hackers-actively-exploiting-ivanti-vpn-vulnerability\/\">Chinese Hackers Actively Exploiting Ivanti VPN Vulnerability to Deploy Malware<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/chinese-hackers-actively-exploiting-ivanti-vpn-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Chinese Hackers Actively Exploiting Ivanti VPN Vulnerability to Deploy Malware Security researchers have identified a critical vulnerability in Ivanti Connect Secure (ICS) VPN appliances that is being actively exploited by suspected Chinese threat actors. The vulnerability, tracked as CVE-2025-22457, is a buffer overflow flaw affecting ICS version 22.7R2.5 and earlier that can lead to remote [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[63,649,131],"tags":[130],"class_list":["post-3054","post","type-post","status-publish","format-standard","hentry","category-cyber-security-news","category-threats","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3054"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=3054"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3054\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=3054"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=3054"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=3054"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}