SPAWNMOLE is a C-based, 32-bit ELF tunneling implant targeting Linux-based Ivanti Connect Secure VPN appliances. It is part of the SPAWN malware ecosystem and provides SOCKS5 proxy functionality by hijacking a process and hooking its communication functions. It tunnels attacker traffic through compromised appliances to evade network defenses. In earlier SPAWN implementations, SPAWNMOLE forwarded malicious traffic over a local TCP connection to the SPAWNSNAIL SSH backdoor for processing.
SPAWNMOLE is deployed alongside SPAWNSNAIL, the SPAWNANT installer, and the SPAWNSLOTH log-tampering utility. SPAWNANT persistently installs SPAWNMOLE and other components, supporting stealthy, long-term access to compromised appliances. Its use is associated with UNC5221, a suspected China-nexus espionage actor, including activity initially tracked as UNC5337 and subsequently merged into UNC5221. Deployments have occurred in Ivanti exploitation campaigns, including those involving CVE-2025-0282. Updated SPAWNMOLE functionality was later incorporated into the consolidated SPAWNCHIMERA implant.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025-0282, a zero-day vulnerability, has been exploited since December 2024, enabling unauthenticated remote code execution. | SPAWNMOLE /root/home/lib/libsocks5.so Tunneler
UNC5221 is a suspected China-nexus actor that Mandiant is tracking as the only group exploiting CVE-2023-46805 and CVE-2024-21887 during the pre-disclosure time frame since early Dec. 2023.
UNC5330 has been observed chaining CVE-2024-21893 and CVE-2024-21887 to compromise Ivanti Connect Secure VPN appliances as early as Feb. 2024. Post-compromise activity by UNC5330 includes deployment of PHANTOMNET and TONERJAM.
It includes multiple modules with diverse capabilities: SPAWNMOLE: SOCKS5 tunneler
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The SPAWN ecosystem of malware ... includes ... SPAWNMOLE tunneler.
The SPAWN ecosystem of malware ... includes ... SPAWNMOLE tunneler.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A SPAWNCHIMERA module that provides SOCKS5 tunneling/proxying to route attacker traffic through the compromised appliance for internal access and operational concealment.
Component malware whose functionality is incorporated into the SPAWNCHIMERA framework.
SPAWN-family component that previously forwarded received malicious traffic to SPAWNSNAIL through 127.0.0.1:8300. Its updated functionality is consolidated into SPAWNCHIMERA, which instead uses UNIX-domain sockets for communication between injected processes.
A tunnelling component used to evade network defenses and support covert communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.