A China-linked threat actor has been actively exploiting recently patched security flaws in Ivanti Endpoint Manager Mobile (EPMM) software, targeting organizations across Europe, North America, and Asia-Pacific regions.
## Vulnerability Details
The attack chain involves two critical vulnerabilities:
– CVE-2025-4427 (CVSS: 5.3)
– CVE-2025-4428 (CVSS: 7.2)
When combined, these flaws allow unauthenticated attackers to execute arbitrary code on vulnerable systems. Ivanti released patches for these vulnerabilities last week.
## Threat Actor Profile
EclecticIQ attributes the exploitation to UNC5221, a Chinese cyber espionage group with a history of targeting edge network appliances since 2023. The same group was recently linked to attacks against vulnerable SAP NetWeaver instances.
The earliest exploitation activity dates back to May 15, 2025, with attacks focusing on multiple sectors:
– Healthcare
– Telecommunications
– Aviation
– Municipal government
– Finance
– Defense
## Attack Methodology
The attackers demonstrate sophisticated knowledge of EPMM’s architecture, following a multi-stage approach:
1. Target the “/mifs/rs/api/v2/” endpoint to establish a reverse shell
2. Deploy KrustyLoader, a Rust-based malware loader
3. Deliver secondary payloads including Sliver
4. Access the MIFS database using hard-coded MySQL credentials
5. Exfiltrate sensitive data including information about managed devices, LDAP users, and Office 365 tokens
6. Use obfuscated shell commands for reconnaissance
7. Deploy Fast Reverse Proxy (FRP) for lateral movement
Researchers also identified connections to Auto-Color, a Linux backdoor previously used against universities and government organizations in North America and Asia.
## Early Warning Signs
GreyNoise reported increased scanning activity targeting Ivanti Connect Secure and Pulse Secure products before the vulnerabilities were disclosed, highlighting how scanning often precedes zero-day exploitation.
Given EPMM’s role in managing enterprise mobile devices, successful exploitation could potentially compromise thousands of devices across targeted organizations.
