TRAILBLAZE is a minimal, in-memory dropper written in bare C using raw system calls. It targets Ivanti Connect Secure VPN appliances and injects a hook into an existing web-service process to load the BRUSHFIRE passive backdoor into a code cave within that process. This process-injection approach places the payload inside a legitimate running service. The deployment is non-persistent and must be repeated after the affected process or appliance restarts.
TRAILBLAZE is deployed through a shell-script dropper during post-exploitation activity. It was observed in intrusions beginning in mid-March 2025 involving exploitation of CVE-2025-22457, a buffer overflow enabling remote code execution on vulnerable Ivanti Connect Secure appliances. The activity is associated with UNC5221, a suspected China-nexus espionage actor focused on edge devices, and included deployment of BRUSHFIRE and malware from the SPAWN ecosystem. BRUSHFIRE hooks TLS read operations to recognize specially formatted incoming data and execute embedded encrypted shellcode.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The earliest evidence of observed CVE-2025-22457 exploitation occurred in mid-March 2025. Following successful exploitation, we observed the deployment of two newly identified malware families, the TRAILBLAZE in-memory only dropper and the BRUSHFIRE passive backdoor. | TRAILBLAZE is an in-memory only dropper written in bare C that uses raw syscalls and is designed to be as minimal as possible.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TRAILBLAZE is an in-memory only dropper written in bare C that uses raw syscalls and is designed to be as minimal as possible.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
"Mandiant observed the deployment of two newly identified malware families ... through a shell script dropper."
TrickBot injects into the svchost.exe process. TRAILBLAZE has injected a hook into an existing process to load BRUSHFIRE in the spaces allocated memory to include the Ivanti Connect Secure (ICS) web process named web.
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
"TRAILBLAZE leverages raw syscalls and Base64 encoding to stay lightweight"
TrickBot injects into the svchost.exe process. TRAILBLAZE has injected a hook into an existing process to load BRUSHFIRE in the spaces allocated memory to include the Ivanti Connect Secure (ICS) web process named web.
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
Examples throughout the content include deleting tools, logs, malware-related files, staged archives, screenshots, temporary files, and exfiltrated data 'to cover their tracks,' 'reduce their footprint,' 'remove traces of activity,' or as part of 'post-intrusion cleanup.'
The content repeatedly describes adversaries and malware deleting files, directories, droppers, scripts, logs, archives, staged data, and other artifacts from compromised systems, e.g., 'APT29 has used SDelete to remove artifacts from victim networks' and 'Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim.'
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware deployed via exploitation of Ivanti Connect Secure CVE-2025-22457 (as described).
An in-memory dropper deployed post-exploitation on Ivanti Connect Secure appliances; injected into a live web process via shell script, designed for stealth (no persistence), and described as lightweight using raw syscalls and Base64 encoding.
An in-memory dropper deployed after exploitation of Ivanti Connect Secure devices.
Malware that injects into an existing process to load BRUSHFIRE into allocated memory within the ICS web process.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.