TRAILBLAZE — Malware Profile

TRAILBLAZE is an in-memory dropper used to deploy the passive backdoor BRUSHFIRE. First reported in March 2025, TRAILBLAZE has been observed in operations attributed to People's Republic of China (PRC) state-sponsored affiliated actors, including UNC5221 and SYLVANITE.

MITRE ATT&CK techniques (4)

Exploited vulnerabilities

Read the full analysis on IntelFusions