Chinese cyber spies are using Ivanti EPMM flaws to breach EU, US organizations
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-4428 +1 in the same advisory: …4427 | Authenticated Code Injection RCE in Ivanti Endpoint Manager Mobile (EPMM) API CVE-2025-4428 is a code injection flaw (CWE-94) in the API component of Ivanti Endpoint Manager Mobile (EPMM) that lets an authenticated, low-privileged remote attacker execute arbitrary code by sending crafted API requests. Successful exploitation yields code execution on the MDM server itself (CVSS 8.8, High), which typically holds device inventory and administrative control over an organization's enrolled mobile fleet. Any organization running EPMM 12.5.0.0 or earlier is in scope. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-05-19, EPSS puts the 30-day exploitation probability at 86% (100th percentile), and public reporting ties limited attacks to the China-linked actor UNC5221, who reportedly began exploiting it alongside the companion API authentication bypass CVE-2025-4427 shortly after disclosure. CISA has also warned that threat actors exploiting these EPMM flaws deploy two malware strains; ransomware involvement has not been confirmed. Do: Upgrade every EPMM instance running 12.5.0.0 or earlier to the patched release per Ivanti's security advisory, prioritizing internet-facing servers, and note that federal agencies must satisfy the BOD 22-01 required action (patch, apply vendor mitigations, or discontinue use of the product). If patching is delayed, restrict internet exposure of the API and review EPMM logs and the advisory's indicators of compromise, since attackers have chained this flaw with the CVE-2025-4427 authentication bypass and deployed malware. Treat any unpatched, exposed EPMM instance as actively targeted until it is remediated. | 8.8 group max | 86% | KEV |
| largetens of thousands of enterprise deployments (order of 10k-100k EPMM servers; many are internet-exposed) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 11.12.0.5 | ade their instances to one of the following fixed versions: 11.12.0.5, 12.3.0.2, 12.4.0.2, or 12.5.0.1. The company also pointed |
| ipv4 | 12.3.0.2 | nstances to one of the following fixed versions: 11.12.0.5, 12.3.0.2, 12.4.0.2, or 12.5.0.1. The company also pointed out that i |
| ipv4 | 12.4.0.2 | o one of the following fixed versions: 11.12.0.5, 12.3.0.2, 12.4.0.2, or 12.5.0.1. The company also pointed out that if they app |
Full article503 words · extracted from helpnetsecurity.com · click to collapse
CVE-2025-4427 and CVE-2025-4428 – the two Ivanti Endpoint Manager Mobile (EPMM) vulnerabilities that have been exploited in the wild as zero-days and patched by Ivanti last week – are being leveraged by a Chinese cyber espionage group that has been exploiting zero-days in edge network appliances since at least 2023, EcleticIQ researchers have shared.
Among the entities targeted in this campaign were:
- a local government authority and healthcare organizations in the UK;
- a research institute, a legal firm, a telco and a manufacturer in Germany;
- an aerospace leasing company in Ireland;
- a healthcare provider, a medical device manufacturer, a firearms manufacturer, and even a cybersecurity firm specializing in mobile threat defense and enterprise device security in the US;
- a multinational bank operating in South Korea;
- a Japanese automotive parts supplier.
The attack campaign
By chaining together the two vulnerabilities, the attackers could achieve remote code execution on internet-exposed Ivanti EPMM deployments without having to authenticate themselves first.
They set up a reverse shell on the compromised systems, deployed KrustyLoader malware downloaded from publicly accessible Amazon AWS S3 buckets, the Sliver backdoor/implant, and an open-source reverse proxy tool.
They also managed to extract data from the Ivanti EPMM databases: data related to the managed mobile devices (IMEI, phone numbers, location, etc.), LDAP users, and Office 365 refresh and access tokens.
EclecticIQ does not mention whether the compromised instances were deployed by the organizations on-premises or in their cloud environment, but judging by some overlapping indicators of compromise, Wiz researchers have spotted the same activities by the same Chinese threat actor, which is tracked as UNC5221.
“We can confirm that the incident we found was on cloud hosted virtual appliances and not an on-prem device. This doesn’t mean that the attacker explicitly targeted cloud environments – from an outside network perspective it is hard to differentiate the two deployment options – but it does mean that both cloud and on-prem customers are at risk,” Gili Tikochinski, researcher at Wiz, told Help Net Security.
EclecticIQ researchers say that UNC5221 demonstrated a deep understanding of EPMM’s internal architecture by repurposing legitimate system components for data exfiltration.
“Given EPMM’s role in managing and pushing configurations to enterprise mobile devices, a successful exploitation could allow threat actors to remotely access, manipulate, or compromise thousands of managed devices across an organization,” they added.
Also, one of the IP addresses associated with these attacks points to UNC5221 also being the ones that exploited vulnerable SAP NetWeaver installations earlier this month.
Patch and search for evidence of compromise
Organizations using Ivanti EPMM should upgrade their instances to one of the following fixed versions: 11.12.0.5, 12.3.0.2, 12.4.0.2, or 12.5.0.1.
The company also pointed out that if they apply the patch see a 400 response in their logs, it does not indicate exploitation.
They did not share any indicators of compromise, but both Wiz and EclecticIQ have, so organizations can look for them.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/05/23/chinese-cyber-spies-are-using-ivanti-epmm-flaws-to-breach-eu-us-organizations/