SPAWNCHIMERA is a SPAWN-family malware framework developed for Ivanti Connect Secure VPN appliances and associated with exploitation of Ivanti edge-device vulnerabilities including CVE-2025-0282; related reporting also places it in post-exploitation activity tied to CVE-2025-22457. It is assessed to be used in China-nexus espionage operations and has been linked in public reporting to clusters tracked as UNC5337 and the broader UNC5221 activity set. Victimology spans government, telecommunications, finance, automotive, chemical, and other sectors across multiple countries.
SPAWNCHIMERA combines capabilities previously associated with SPAWNANT, SPAWNMOLE, and SPAWNSNAIL, and is commonly described as a toolkit rather than a single simple implant. Reported modules include an installer component, a SOCKS5 tunneling component, an SSH backdoor component, and a log-wiping component in the broader SPAWN ecosystem. The malware is designed specifically for compromised Ivanti appliances, enabling covert remote access and follow-on intrusion activity after initial exploitation of the VPN gateway.
Documented behavior includes establishing covert command-and-control through SSH tunneling, use of port knocking or TLS-based traffic gating to restrict operator access, modification of timestamps for defense evasion, checks for SELinux status on targeted hosts, and tampering with Ivanti integrity-checking mechanisms to reduce detection. Reporting also states that it can generate RSA keys to sign modified manifest data so altered components appear legitimate, and that it includes functionality intended to block reinfection or competing exploitation by other actors. Public reporting on the successor variant RESURGE states that RESURGE builds directly on SPAWNCHIMERA and inherits reboot-survival functionality, indicating SPAWNCHIMERA itself had persistence mechanisms on compromised appliances.
SPAWNCHIMERA has been deployed in campaigns targeting Ivanti Connect Secure devices as an initial foothold into enterprise and government environments, after which operators can pivot into internal networks and conduct broader espionage operations. Detection is complicated by appliance-focused tradecraft, layered command-and-control, integrity-checker tampering, and log suppression or wiping within the SPAWN ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025-0282 (CVSS skóre 9,0) Kritická zraniteľnosť spočíva v pretečení zásobníka a vzdialený neautentifikovaný útočník by ju mohol zneužiť na vzdialené vykonanie kódu. CVE-2025-0282 je v súčasnosti aktívne zneužívaná na kompromitáciu Ivanti Connect Secure a následnú inštaláciu malvéru. | JPCERT/CC zverejnil informácie, že zraniteľnosť CVE-2025-0282 je v súčasnosti aktívne zneužívaná na šírenie malwarového frameworku SPAWNCHIMERA.
Similarly, CVE-2025-22457 is also attributed to a stack-based buffer overflow weakness. This vulnerability impacts a range of Ivanti products, including Pulse Connect Secure 9.1x and Ivanti Connect Secure 22.7R2.5 and earlier... Ivanti released a patch for this vulnerability on February 11, 2025.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
----[ 2.7 Spawn Chimera and The Hankyoreh Drop Location: mnt/hgfs/Desktop/New folder/203.234.192.200_client.zip The client accesses the SpawnChimera backdoor via port knocking.
Mandiant ... reported that attackers began leveraging this vulnerability as early as mid-December, deploying the custom Spawn malware toolkit... TeamT5 reports that the threat actor used SPAWNCHIMERA, a malware toolkit developed specifically for Ivanti VPN appliances.
Mandiant ... reported that attackers began leveraging this vulnerability as early as mid-December, deploying the custom Spawn malware toolkit... TeamT5 reports that the threat actor used SPAWNCHIMERA, a malware toolkit developed specifically for Ivanti VPN appliances.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes adversaries using Base64, XOR, RC4, AES, hexadecimal encoding, string encryption, code flattening, custom crypters, and other obfuscation methods to hide payloads, strings, configuration data, URLs, and scripts.
The content repeatedly describes adversaries and malware deleting files, directories, droppers, scripts, logs, archives, staged data, and other artifacts from compromised systems, e.g., 'APT29 has used SDelete to remove artifacts from victim networks' and 'Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim.'
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
The content repeatedly describes threat actors and malware using valid, stolen, forged, self-signed, or abused code-signing certificates to sign malware and appear legitimate, including examples such as AppleJeus using a valid digital signature from Sectigo, APT41 leveraging code-signing certificates, FIN7 signing Carbanak payloads, and SUNBURST being digitally signed by SolarWinds.
The content repeatedly describes threat actors and malware disabling or modifying security tools, EDR/AV, logging, firewall rules, integrity checkers, and security settings; e.g., 'Agrius used several mechanisms to try to disable security tools' and 'BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.'
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prior SPAWN-family malware with reboot-surviving persistence; described as the predecessor/base that RESURGE extends with additional commands and expanded capabilities.
Referenced as a related malware/tool with similar SSH-tunnel C2 behavior to RESURGE; no additional functional details provided in the content.
Referenced as a malware variant whose capabilities overlap with RESURGE (e.g., surviving reboots).
SPAWNCHIMERA is a malware family delivered via exploitation of Ivanti Connect Secure vulnerabilities. Specific functionality is not detailed in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.