Executive Summary
In May 2025, advanced threat actors exploited two zero-day vulnerabilities (CVE-2025-4427 and CVE-2025-4428) in Ivanti Endpoint Manager Mobile (EPMM), targeting on-premise deployments. Attackers used an authentication bypass and code injection to deliver modular malware kits via crafted API requests, enabling them to gain initial access, perform reconnaissance, harvest credentials, and establish persistence within target environments. While Ivanti released patches shortly after discovery, the exploits were reportedly active before disclosure, affecting a limited set of organizations—primarily through an advanced persistent threat (APT) operation attributed by third-party researchers to a China-nexus espionage group.
This incident underscores the growing trend of sophisticated supply chain and zero-day attacks on enterprise mobile device management (MDM) platforms, which are increasingly treated as high-value assets due to their access to sensitive business operations. Organizations must remain vigilant by prioritizing comprehensive patch management and strengthening internal traffic monitoring to mitigate similar risks.
Why This Matters Now
The Ivanti EPMM breach reveals how nation-state attackers are rapidly exploiting zero-day vulnerabilities in critical infrastructure products before vendors can patch, highlighting the urgency for organizations to treat MDM tools as high-value assets, enforce segmentation, and accelerate incident response to prevent widespread data exfiltration and persistence.
Attack Path Analysis
Attackers exploited Ivanti EPMM vulnerabilities to gain unauthorized API access via HTTP GET requests, bypassing authentication to establish a foothold. They leveraged their access to inject malicious code, enabling them to escalate privileges and gain persistent control. Using their foothold, the attackers performed reconnaissance and potentially moved laterally within the environment to target sensitive resources. Custom malware set up command and control channels using HTTP for continuous remote operations. The threat actors exfiltrated system information and LDAP credentials, repurposing EPMM components for data theft. The attack resulted in persistent unauthorized access and risk of further business impact until systems were isolated.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited authentication bypass (CVE-2025-4427) and code injection (CVE-2025-4428) in Ivanti EPMM's API to gain initial access via crafted HTTP GET requests.
Related CVEs
CVE-2025-4427
CVSS 9.8An authentication bypass in the API component of Ivanti Endpoint Manager Mobile allows attackers to access protected resources without proper credentials via the API.
Affected Products:
Ivanti Endpoint Manager Mobile – 12.5.0.0 and prior
Exploit Status:
exploited in the wildCVE-2025-4428
CVSS 9.8A code injection vulnerability in Ivanti Endpoint Manager Mobile allows attackers to execute arbitrary code on the server.
Affected Products:
Ivanti Endpoint Manager Mobile – 12.5.0.0 and prior
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Create Account
Process Injection: Dynamic-link Library Injection
Obfuscated Files or Information
Application Layer Protocol: Web Protocols
Data from Local System
Windows Management Instrumentation
OS Credential Dumping
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Timely Identification and Patching of Security Vulnerabilities
Control ID: 6.2.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 10
CISA ZTMM 2.0 – Continuous Monitoring and Analytics
Control ID: 5.1
NIS2 Directive – Incident Handling and Resilience Measures
Control ID: Article 21 (2)(c)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Critical exposure to APT attacks targeting Ivanti EPMM systems managing government mobile devices, requiring immediate patching and enhanced MDM security monitoring.
Health Care / Life Sciences
High-value target for China-nexus espionage exploiting mobile device management vulnerabilities, risking HIPAA compliance violations and patient data exfiltration through LDAP credential theft.
Financial Services
Advanced persistent threats exploiting Ivanti EPMM authentication bypass vulnerabilities threaten financial institution mobile security infrastructure and regulatory compliance requirements.
Information Technology/IT
IT organizations face direct exposure to zero-day exploits in enterprise mobile management systems, requiring immediate forensic analysis and security fabric implementation.
Sources
- CISA exposes malware kits deployed in Ivanti EPMM attackshttps://www.bleepingcomputer.com/news/security/cisa-exposes-malware-kits-deployed-in-ivanti-epmm-attacks/Verified
- CISA Releases Malware Analysis Report on Malicious Listener Targeting Ivanti Endpoint Manager Mobile Systemshttps://www.cisa.gov/news-events/alerts/2025/09/18/cisa-releases-malware-analysis-report-malicious-listener-targeting-ivanti-endpoint-manager-mobileVerified
- Malicious Listener for Ivanti Endpoint Mobile Management Systemshttps://www.cisa.gov/news-events/analysis-reports/ar25-261aVerified
- CISA and International Partner NCSC-NO Release Joint Cybersecurity Advisory on Threat Actors Exploiting Ivanti EPMM Vulnerabilitieshttps://www.cisa.gov/news-events/alerts/2023/08/01/cisa-and-international-partner-ncsc-no-release-joint-cybersecurity-advisory-threat-actors-exploitingVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust, microsegmentation, east-west isolation, and egress policy enforcement would have limited the attackers’ movement and capability to perform malicious actions at multiple kill chain stages. Enhanced traffic visibility and threat detection could have rapidly surfaced anomalous behavior, limiting potential impact.
Control: Inline IPS (Suricata)
Mitigation: Known exploit patterns and malicious payloads blocked or detected at network ingress.
Control: Zero Trust Segmentation
Mitigation: Access between workloads restricted to enforce least privilege.
Control: East-West Traffic Security
Mitigation: Lateral movement contained with workload-to-workload controls and network microsegmentation.
Control: Threat Detection & Anomaly Response
Mitigation: Anomalous command & control patterns rapidly detected and alerted.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound exfiltration attempts blocked or flagged.
Centralized observability enables real-time identification and containment of compromised assets.
Impact at a Glance
Affected Business Functions
- Mobile Device Management
- IT Security Operations
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of personally identifiable information (PII) such as names, phone numbers, and other mobile device details of users on the vulnerable system.
Recommended Actions
Key Takeaways & Next Steps
- • Patch Ivanti EPMM systems immediately and continuously monitor for published IOCs and malicious payloads.
- • Implement Zero Trust segmentation and east-west traffic policies to contain lateral movement from compromised services.
- • Enforce strict egress filtering and outbound policy controls to block data exfiltration and unauthorized connections.
- • Deploy Inline IPS, anomaly detection, and threat response to rapidly detect and disrupt network-based exploits and command & control activity.
- • Establish centralized multicloud visibility to detect compromise across hybrid environments and enable rapid host isolation and response.



