TRAILBLAZE
S9012 · Linux, Network Devices
TRAILBLAZE is an in-memory dropper used to deploy the passive backdoor BRUSHFIRE. First reported in March 2025, TRAILBLAZE has been observed in operations attributed to People's Republic of China (PRC) state-sponsored affiliated actors, including UNC5221 and SYLVANITE.
ATT&CK S9012
Sigma rules0
YARA rules0
Live IOCs0