In this episode of Cyber Insiders, Cian Heasley, Threat Lead at Adarma, walks us through our Incident Response team's investigation into the exploitation of Ivanti Endpoint Manager Mobile (EPMM) by UNC5221, a threat group linked to the Chinese state.
Cian breaks down how the attackers chained CVE-2025-4427 and CVE-2025-4428 to gain unauthenticated remote code execution, what tools and techniques they used, and explains why this campaign shows signs of strategic pre-positioning.