TRAILBLAZE is an in-memory-only dropper associated with exploitation of Ivanti Connect Secure appliances compromised via CVE-2025-22457. It has been linked to activity attributed to UNC5221, a suspected China-nexus espionage actor known for targeting edge devices. TRAILBLAZE is a minimal implant written in bare C, uses raw syscalls, and is designed to be embedded as Base64-encoded content within a shell-script dropper. After successful exploitation, the dropper executes TRAILBLAZE and uses it to inject the BRUSHFIRE passive backdoor into the Ivanti web process, enabling stealthy post-compromise access while avoiding persistence. Observed tradecraft emphasized memory-only execution, cleanup of temporary artifacts, and operation inside an existing live web service process rather than installing durable footholds. The malware’s role in the intrusion chain is post-exploitation payload staging and in-memory deployment of follow-on tooling on Linux-based edge appliances.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Post-exploitation activity includes deploying newly identified malware: TRAILBLAZE (in-memory dropper) and BRUSHFIRE (passive backdoor). | Mandiant (part of Google Cloud) is releasing details on active exploitation of a critical buffer overflow vulnerability, CVE-2025-22457, impacting Ivanti Connect Secure (ICS) VPN appliances (versions 22.7R2.5 and earlier). We identified the suspected China-nexus espionage actor UNC5221 exploiting this flaw in the wild for remote code execution in their operations, dating back to mid-March.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Post-exploitation activity includes deploying newly identified malware: TRAILBLAZE (in-memory dropper) and BRUSHFIRE (passive backdoor).
12 distinct techniques documented for this family, organized by ATT&CK tactic.
"Mandiant observed the deployment of two newly identified malware families ... through a shell script dropper."
TrickBot injects into the svchost.exe process. TRAILBLAZE has injected a hook into an existing process to load BRUSHFIRE in the spaces allocated memory to include the Ivanti Connect Secure (ICS) web process named web.
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
"TRAILBLAZE leverages raw syscalls and Base64 encoding to stay lightweight"
TrickBot injects into the svchost.exe process. TRAILBLAZE has injected a hook into an existing process to load BRUSHFIRE in the spaces allocated memory to include the Ivanti Connect Secure (ICS) web process named web.
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
Examples throughout the content include deleting tools, logs, malware-related files, staged archives, screenshots, temporary files, and exfiltrated data 'to cover their tracks,' 'reduce their footprint,' 'remove traces of activity,' or as part of 'post-intrusion cleanup.'
The content repeatedly describes adversaries and malware deleting files, directories, droppers, scripts, logs, archives, staged data, and other artifacts from compromised systems, e.g., 'APT29 has used SDelete to remove artifacts from victim networks' and 'Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim.'
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware deployed via exploitation of Ivanti Connect Secure CVE-2025-22457 (as described).
An in-memory dropper deployed post-exploitation on Ivanti Connect Secure appliances; injected into a live web process via shell script, designed for stealth (no persistence), and described as lightweight using raw syscalls and Base64 encoding.
An in-memory dropper deployed after exploitation of Ivanti Connect Secure devices.
Malware that injects into an existing process to load BRUSHFIRE into allocated memory within the ICS web process.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.