SPAWNSLOTH is a SPAWN malware ecosystem component used against Ivanti Connect Secure appliances. It is a Linux-based log-tampering utility associated with suspected China-nexus intrusion activity, including operations tracked as UNC5337 and broader activity linked to UNC5221. Its primary role is defense evasion: removing or suppressing evidence of compromise on affected Ivanti devices to hinder detection and incident response.
SPAWNSLOTH has been described as a log wiper or log-tampering tool and has been observed both as a standalone SPAWN-family component and as a variant embedded within the RESURGE implant. On compromised Ivanti appliances, it tampers with device logs to hide malicious activity. Reported behavior includes targeting the logging subsystem to disable local logging and remote syslog forwarding, thereby reducing forensic visibility and helping operators conceal post-exploitation actions.
The malware has been observed in intrusion chains following exploitation of Ivanti Connect Secure vulnerabilities, including campaigns involving CVE-2023-46805, CVE-2024-21887, CVE-2024-21893, CVE-2025-0282, and CVE-2025-22457. It appears alongside other SPAWN-family components such as SPAWNSNAIL, SPAWNMOLE, SPAWNANT, SPAWNSNARE, SPAWNCHIMERA, SPAWNWAVE, and RESURGE, indicating use as a specialized anti-forensics module within a broader post-compromise toolkit for edge-device espionage and persistence operations.
Victimology associated with the surrounding campaigns includes enterprises, government environments, critical infrastructure, and multiple industries globally that rely on Ivanti Connect Secure VPN appliances for remote access. SPAWNSLOTH itself is best characterized as a focused anti-forensics utility rather than a full-featured implant, with its core purpose being concealment of attacker activity on compromised network edge devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
UNC5337 leveraged multiple custom malware families including the SPAWNSNAIL passive backdoor, SPAWNMOLE tunneler, SPAWNANT installer, and SPAWNSLOTH log tampering utility.
UNC5337 leveraged multiple custom malware families including the SPAWNSNAIL passive backdoor, SPAWNMOLE tunneler, SPAWNANT installer, and SPAWNSLOTH log tampering utility.
On April 3, 2025, Ivanti disclosed a critical vulnerability, CVE-2025-22457, affecting Ivanti Connect Secure (ICS) VPN appliances version 22.7R2.5 and earlier. The flaw, initially underestimated as a denial-of-service risk, was later found to be a buffer overflow that allows remote code execution. Mandiant observed exploitation beginning in mid-March 2025... | The actor also used other SPAWN components such as SPAWNSLOTH (log tampering), SPAWNSNARE (kernel image extraction and encryption), and SPAWNWAVE (an evolved implant utility).
Researchers believe a China-linked threat actor, UNC5221, exploited the CVE-2025-0282 vulnerability as a zero-day since mid-December 2024.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC5337 leveraged multiple custom malware families including the SPAWNSNAIL passive backdoor, SPAWNMOLE tunneler, SPAWNANT installer, and SPAWNSLOTH log tampering utility.
UNC5337 leveraged multiple custom malware families including the SPAWNSNAIL passive backdoor, SPAWNMOLE tunneler, SPAWNANT installer, and SPAWNSLOTH log tampering utility.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware/tooling family referenced here as a variant used to tamper with logs on compromised systems to hinder detection and incident response.
Referenced as a malware/tool variant (liblogblock.so) used alongside RESURGE to tamper with logs on compromised Ivanti Connect Secure devices, supporting stealth and defense evasion.
A SPAWN-family log-tampering utility used to erase or manipulate Ivanti device logs to remove evidence of compromise and hinder incident response/forensics.
Log-tampering component/variant embedded within the RESURGE sample, used to interfere with Ivanti device logging.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.