SPAWNANT is a malware installer and dropper targeting Ivanti Connect Secure VPN appliances. It is part of the modular SPAWN malware ecosystem and persistently installs the SPAWNSNAIL SSH backdoor and SPAWNMOLE tunneler, as well as additional web shells. Its role is to establish and maintain the payloads that support long-term access to compromised edge devices; tunneling, SSH backdoor functionality, and log suppression are provided by separate SPAWN components.
SPAWNANT has been deployed following exploitation of Ivanti vulnerabilities, including in campaigns involving zero-day exploitation of CVE-2025-0282. It is associated with UNC5221, a suspected China-nexus cyberespionage actor, and activity initially tracked as UNC5337 that was subsequently merged into UNC5221. Associated operations have targeted government agencies and organizations across multiple industries and geographic regions. Later SPAWN-family implants, including SPAWNCHIMERA and SPAWNWAVE, incorporate or extend SPAWNANT functionality alongside capabilities from other SPAWN components.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025-0282, a zero-day vulnerability, has been exploited since December 2024, enabling unauthenticated remote code execution. | SPAWNANT /root/lib/libupgrade.so Installer
UNC5330 has been observed chaining CVE-2024-21893 and CVE-2024-21887 to compromise Ivanti Connect Secure VPN appliances as early as Feb. 2024. Post-compromise activity by UNC5330 includes deployment of PHANTOMNET and TONERJAM.
UNC5221 is a suspected China-nexus actor that Mandiant is tracking as the only group exploiting CVE-2023-46805 and CVE-2024-21887 during the pre-disclosure time frame since early Dec. 2023.
It includes multiple modules with diverse capabilities: SPAWNANT: Installer
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Silk Typhoon is described as targeting government agencies with custom malware Zipline and Spawnant in zero-day attacks against Ivanti products.
Its purpose is to persistently install other malware from the SPAWN family (SPAWNSNAIL, SPAWNMOLE) as well as drop additional webshells on the box.
UNC5337 leveraged SPAWNANT, an installer targeting Ivanti devices.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware associated with Silk Typhoon's attacks targeting government agencies through Ivanti product zero-days. Its specific capabilities are not described; it appears as background context in this report about Dell vulnerabilities.
Custom malware attributed to UNC5221, used in operations exploiting Ivanti zero-days against government agencies.
Custom malware used by UNC5221 in campaigns exploiting Ivanti zero-days against government agencies (functionality not described in the content).
Custom malware associated with UNC5221 activity, referenced in the context of Ivanti zero-day exploitation against government agencies.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.