Two recently patched vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) software allowed a cyberespionage campaign by the UNC5221 group , a group of Chinese hackers . The attacks, recorded in Europe, North America and Asia-Pacific , targeted sensitive sectors such as healthcare, telecommunications, aviation, local government, finance and defense.

The two vulnerabilities — CVE-2025-4427 and CVE-2025-4428, with CVSS scores of 5.3 and 7.2 respectively — can be combined to allow remote code execution without the need for user authentication. Ivanti released security updates last week, but the first signs of active exploitation have been detected as early as May 15, according to an analysis by Dutch cybersecurity firm EclecticIQ.
UNC5221 reportedly has deep knowledge of the EPMM architecture, even using legitimate system components to steal data . As researcher Arda Büyükkaya notes , successful exploitation of the Ivanti vulnerabilities could allow full remote access and control over thousands of corporate mobile devices .
See also: Chrome vulnerabilities allow malicious code execution
UNC5221's Moves: Advanced Ivanti EPMM Exploitation
The recent campaign by Chinese hackers UNC5221 involves a well-organized sequence of actions targeting Ivanti Endpoint Manager Mobile (EPMM).
According to EclecticIQ, the attackers exploit the “/mifs/rs/api/v2/” endpoint to obtain an interactive reverse shell, which allows them to remotely execute commands without authorization. In a next step, they install KrustyLoader — a malware written in Rust — which acts as a platform for delivering additional malicious tools, including Sliver.
The attackers also gain access to the mifs database by exploiting hard-coded MySQL database credentials stored in /mi/files/system/.mifpp. Through this tactic, they gain access to sensitive data , including information about managed devices, LDAP users, and tokens associated with Office 365 accounts.
See also: Cisco patches high-severity DoS vulnerability
Before installing KrustyLoader, the team performs target identification using obfuscated shell commands.

EclecticIQ also identified a command-and-control (C2) server associated with Auto-Color, a Linux backdoor that had been recorded by Palo Alto Networks Unit 42 in attacks against universities and government organizations in North America and Asia (between November and December 2024).
“The IP address 146.70.87[.]67:45020, previously associated with the Auto-Color command and control infrastructure, appeared to issue outbound connectivity tests via curl immediately after the Ivanti EPMM servers were exploited,” Büyükkaya noted. “This behavior is consistent with Auto-Color’s staging and beaconing patterns . Overall, these indicators are highly likely to be associated with Chinese hacker activity.”
The attacks described above are worrisome for many reasons — not only for their technical complexity, but also for their geopolitical and operational implications.
See also: Samlify SSO bug allows login as administrator
First, they clearly demonstrate how attractive mobile endpoint managers (like Ivanti EPMM) are as targets. These systems handle large amounts of sensitive data and provide broad access to devices and services, making them ideal for lateral movement within networks. The fact that exploiting the vulnerabilities does not require authentication makes the threat even more serious.
Source: thehackernews.com
