• News/
  • https://www.bleepingcomputer.com/news/security/cisa-exposes-malware-kits-deployed-in-ivanti-epmm-attacks/

CISA exposes malware kits deployed in Ivanti EPMM attacks

BleepingComputer
·
Ionut Ilascu
·
Published Sep 19, 2025
·
Updated

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published an analysis of the malware deployed in attacks exploiting vulnerabilities affecting Ivanti Endpoint Manager Mobile (EPMM). The flaws are an authentication bypass in EPMM’s API component (CVE-2025-4427) and a code injection vulnerability (CVE-2025-4428) that allows execution of arbitrary code. The two vulnerabilities affect the following Ivanti EPMM development branches and their earlier releases: 11.12.0.4, 12.3.0.1, 12.4.0.1, and 12.5.0.0. Ivanti addressed the issues on May 13, but threat actors had already been exploiting them as zero days in attacks against “a very limited number of customers.” About a week later, threat intelligence platform EclecticIQ reported with high confidence that a China-nexus espionage group was leveraging the two vulnerabilities since at least May 15. The researchers said that the China-linked threat actor is very knowledgeable of Ivanti EPMM's internal architecture, being capable of repurposing system components to exfiltrate data. CISA’s report, though, does not make any attribution and focuses only on the technical details of malicious files obtained from an organization attacked by threat actors using an exploit chain for CVE-2025-4427 and CVE-2025-4428. The U.S. agency analyzed two sets of malware consisting of five files that the hackers used to gain initial access to on-premise Ivanti EPMM systems. “The cyber threat actors targeted the /mifs/rs/api/v2/ endpoint...

Read full article

Affected Software

4 affected components
Ivanti Endpoint Manager Mobile=11.12.0.4
Ivanti Endpoint Manager Mobile=12.3.0.1
Ivanti Endpoint Manager Mobile=12.4.0.1
Ivanti Endpoint Manager Mobile=12.5.0.0
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the malware kits used in attacks against Ivanti Endpoint Manager Mobile (EPMM) vulnerabilities as analyzed by CISA.

2

What security implications are discussed in the article?

The article highlights the risks of an authentication bypass and code injection vulnerabilities in Ivanti EPMM that can lead to unauthorized access and malware deployment.

3

What specific vulnerabilities are mentioned in the article?

The vulnerabilities mentioned include an authentication bypass in the API component (CVE-2025-4427) and a code injection issue.

4

What software products are mentioned as affected by the vulnerabilities?

Ivanti Endpoint Manager Mobile (Ivanti) is identified as the software affected by the vulnerabilities and associated malware attacks.

5

Who published the analysis regarding the malware kits?

The analysis regarding the malware kits was published by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203