BRUSHFIRE is a passive backdoor associated with exploitation of Ivanti Connect Secure appliances by the suspected China-nexus espionage actor UNC5221. It was observed in post-compromise activity following exploitation of CVE-2025-22457, where operators used a shell-script dropper and the in-memory dropper TRAILBLAZE to inject BRUSHFIRE into the appliance web process rather than relying on conventional on-disk persistence. The malware is written in bare C and is designed for stealthy in-memory operation on edge devices.
BRUSHFIRE functions by hooking SSL_read in the target web process. It allows the legitimate SSL_read call to proceed, inspects returned data for a specific trigger pattern, and when triggered decrypts embedded shellcode with XOR and executes it in memory. It can also use SSL_write to return output from the executed shellcode. This design enables covert command execution through existing encrypted application traffic while minimizing forensic artifacts and blending with normal appliance operations.
Observed deployment emphasized defense evasion and non-persistent post-exploitation access. Operators injected BRUSHFIRE into a live web service process, cleaned up temporary artifacts, and avoided persistence so the implant would need to be redeployed after reboot or process restart. The malware formed part of a broader intrusion set that also included TRAILBLAZE and components of the SPAWN ecosystem, reflecting a mature edge-device intrusion capability focused on stealth, post-exploitation access, and follow-on operations including data theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Mandiant (part of Google Cloud) is releasing details on active exploitation of a critical buffer overflow vulnerability, CVE-2025-22457, impacting Ivanti Connect Secure (ICS) VPN appliances (versions 22.7R2.5 and earlier). We identified the suspected China-nexus espionage actor UNC5221 exploiting this flaw in the wild for remote code execution in their operations, dating back to mid-March. | Post-exploitation activity includes deploying newly identified malware: TRAILBLAZE (in-memory dropper) and BRUSHFIRE (passive backdoor).
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Post-exploitation activity includes deploying newly identified malware: TRAILBLAZE (in-memory dropper) and BRUSHFIRE (passive backdoor).
9 distinct techniques documented for this family, organized by ATT&CK tactic.
"Mandiant observed the deployment of two newly identified malware families ... through a shell script dropper."
"use of a shell-script dropper to inject TRAILBLAZE and BRUSHFIRE into a live web process, avoiding persistence and focusing on stealth"
"It then deletes all of the temporary files previously created ... as well as the contents of the /data/var/cores directory."
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware deployed via exploitation of Ivanti Connect Secure CVE-2025-22457 (as described).
A passive backdoor injected into a live web process on Ivanti Connect Secure; hooks SSL_read to execute encrypted payloads, emphasizing stealth and avoiding persistence.
A passive backdoor deployed post-exploitation on compromised Ivanti Connect Secure appliances.
Payload loaded by TRAILBLAZE into allocated memory within the ICS web process.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.