BRUSHFIRE

MITRE ATT&CK: S9011 View on attack.mitre.org

Aliases: BRUSHFIRE

First seen
2025-03-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
linux, network-devices
Profile updated
2026-07-07 14:30:11

Targeted industries: government-and-public-sector technology-and-telecommunications energy-and-utilities

Targeted regions: country_code:cn country_code:us

Context

BRUSHFIRE is a passive backdoor written in C that executes in-memory within an existing process. First reported in March 2025, BRUSHFIRE has been observed in activity attributed to People's Republic of China (PRC) state-affiliated threat actors, including UNC5221 and SYLVANITE.

Detection coverage

  • 17 Sigma rules

Malware & tools used

  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Exfiltration Over Asymmetric Encrypted Non-C2 Protocol (attack-pattern)
  • Traffic Signaling (attack-pattern)
  • Reflective Code Loading (attack-pattern)

Exploited vulnerabilities

  • CVE-2025-22457 (vulnerability)

Reports & references

  • cloud.google.com — China Nexus Exploiting Critical Ivanti Vulnerability (report)
  • MITRE ATT&CK — S9011 (report)
  • hub.dragos.com — 2026 Yir Executivebriefing%20O G (report)
  • picussecurity.com — Unc5221 Cve 2025 22457 Ivanti Connect Secure (report)

External references