SPAWNSNAIL is a passive SSH backdoor targeting Linux-based Ivanti Connect Secure VPN appliances. It provides persistent remote access as part of the cooperating SPAWN malware ecosystem. Its capabilities include injecting specified binaries into other processes, running a local SSH backdoor within the appliance's dsmdm process, and injecting additional malware into dslogserver.
SPAWNSNAIL works alongside SPAWNANT, which persistently installs it, and SPAWNMOLE, which forwards malicious traffic to the backdoor. The associated SPAWNSLOTH component suppresses local logging and remote syslog forwarding, helping conceal attacker activity. Together, these components support stealthy, long-term access to compromised edge appliances.
SPAWNSNAIL has been deployed in Ivanti exploitation campaigns, including activity involving CVE-2025-0282. Its use is associated with UNC5221, a suspected China-nexus espionage actor; activity initially tracked as UNC5337 was subsequently merged into UNC5221. Updated SPAWNSNAIL functionality was later incorporated into the combined SPAWNCHIMERA implant.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025-0282, a zero-day vulnerability, has been exploited since December 2024, enabling unauthenticated remote code execution. | SPAWNSNAIL /root/home/lib/libsshd.so SSH backdoor
UNC5330 has been observed chaining CVE-2024-21893 and CVE-2024-21887 to compromise Ivanti Connect Secure VPN appliances as early as Feb. 2024. Post-compromise activity by UNC5330 includes deployment of PHANTOMNET and TONERJAM.
UNC5221 is a suspected China-nexus actor that Mandiant is tracking as the only group exploiting CVE-2023-46805 and CVE-2024-21887 during the pre-disclosure time frame since early Dec. 2023.
It includes multiple modules with diverse capabilities: SPAWNSNAIL: SSH backdoor
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC5337 leveraged the SPAWNSNAIL passive backdoor. Mandiant also discovered the cooperating SPAWN families on an appliance compromised by UNC5221.
SPAWNSNAIL is an SSH backdoor targeting Ivanti devices. It has an ability to inject a specified binary to other process ... as well as injecting additional malware to dslogserver.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
SPAWNSNAIL is an SSH backdoor targeting Ivanti devices. It has an ability to inject a specified binary to other process, running local SSH backdoor when injected to dsmdm process, as well as injecting additional malware to dslogserver
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A SPAWNCHIMERA module that provides SSH-based backdoor access on compromised Ivanti VPN appliances for remote control and persistence.
SPAWN-family component that processed malicious traffic forwarded by SPAWNMOLE through a local TCP connection. Its updated functionality is incorporated into SPAWNCHIMERA.
SSH backdoor that provides persistent remote access on compromised Ivanti appliances.
SSH backdoor observed on compromised Ivanti appliances, located at /root/home/lib/libsshd.so.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.