Chinese Hackers Launch Global Cyberattack Campaign Exploiting Critical Ivanti Vulnerabilities


# Chinese Hackers Exploit Ivanti EPMM Vulnerabilities in Global Cyber Espionage Campaign

A China-linked threat actor has been actively exploiting recently patched security flaws in Ivanti Endpoint Manager Mobile (EPMM) software, targeting organizations across Europe, North America, and Asia-Pacific regions.

## Vulnerability Details

The attack chain involves two critical vulnerabilities:
– CVE-2025-4427 (CVSS: 5.3)
– CVE-2025-4428 (CVSS: 7.2)

When combined, these flaws allow unauthenticated attackers to execute arbitrary code on vulnerable systems. Ivanti released patches for these vulnerabilities last week.

## Threat Actor Profile

EclecticIQ attributes the exploitation to UNC5221, a Chinese cyber espionage group with a history of targeting edge network appliances since 2023. The same group was recently linked to attacks against vulnerable SAP NetWeaver instances.

The earliest exploitation activity dates back to May 15, 2025, with attacks focusing on multiple sectors:
– Healthcare
– Telecommunications
– Aviation
– Municipal government
– Finance
– Defense

## Attack Methodology

The attackers demonstrate sophisticated knowledge of EPMM’s architecture, following a multi-stage approach:

1. Target the “/mifs/rs/api/v2/” endpoint to establish a reverse shell
2. Deploy KrustyLoader, a Rust-based malware loader
3. Deliver secondary payloads including Sliver
4. Access the MIFS database using hard-coded MySQL credentials
5. Exfiltrate sensitive data including information about managed devices, LDAP users, and Office 365 tokens
6. Use obfuscated shell commands for reconnaissance
7. Deploy Fast Reverse Proxy (FRP) for lateral movement

Researchers also identified connections to Auto-Color, a Linux backdoor previously used against universities and government organizations in North America and Asia.

## Early Warning Signs

GreyNoise reported increased scanning activity targeting Ivanti Connect Secure and Pulse Secure products before the vulnerabilities were disclosed, highlighting how scanning often precedes zero-day exploitation.

Given EPMM’s role in managing enterprise mobile devices, successful exploitation could potentially compromise thousands of devices across targeted organizations.

Share This Article