SPAWNCHIMERA is a persistent SPAWN-family backdoor toolkit targeting Linux-based Ivanti Connect Secure VPN appliances. It consolidates updated functionality from the SPAWNANT installer, SPAWNMOLE SOCKS5 tunneler, and SPAWNSNAIL SSH backdoor into a single implant, and drops the SPAWNSLOTH log-tampering component. It provides covert SSH-based command-and-control, traffic tunneling, and access that survives appliance reboots. Deployment has been observed following exploitation of CVE-2025-0282, including incidents in Japan beginning in late December 2024. It has also appeared in campaigns exploiting CVE-2025-22457.
SPAWNCHIMERA injects itself into multiple appliance processes and routes malicious traffic between injected instances using UNIX domain sockets rather than localhost TCP connections, reducing visibility in network information collected by appliance integrity checks. It encodes its embedded SSH private key and decodes it in memory without writing the key to disk. Additional evasion measures include modifying the Ivanti Integrity Checker Tool, manipulating file timestamps, generating RSA keys to sign manifests for modified files, and removing debugging messages. Its associated SPAWNSLOTH component suppresses local logging and remote syslog forwarding. The implant also checks whether SELinux is enabled.
Within the compromised web process, SPAWNCHIMERA hooks the strncpy function and limits copy lengths to dynamically mitigate CVE-2025-0282. This can obstruct subsequent exploitation by competing attackers and vulnerability scanners without removing the existing compromise. SPAWNCHIMERA has been associated with China-nexus espionage activity tracked as UNC5337 and the broader UNC5221 cluster. Campaigns using the toolkit have affected organizations across multiple countries and sectors, including government, telecommunications, financial institutions, automotive, and chemical industries. Related SPAWN-family variants include SPAWNWAVE and RESURGE, which share overlapping functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
遠隔の攻撃者が認証不要で任意のコードを実行する可能性がある脆弱性(CVE-2025-0282)。JPCERT/CCでは、本脆弱性公開前の2024年12月下旬から本脆弱性が悪用された被害を国内で複数確認しています。
Similarly, CVE-2025-22457 is also attributed to a stack-based buffer overflow weakness. This vulnerability impacts a range of Ivanti products, including Pulse Connect Secure 9.1x and Ivanti Connect Secure 22.7R2.5 and earlier... Ivanti released a patch for this vulnerability on February 11, 2025.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
----[ 2.7 Spawn Chimera and The Hankyoreh Drop Location: mnt/hgfs/Desktop/New folder/203.234.192.200_client.zip The client accesses the SpawnChimera backdoor via port knocking.
Mandiant ... reported that attackers began leveraging this vulnerability as early as mid-December, deploying the custom Spawn malware toolkit... TeamT5 reports that the threat actor used SPAWNCHIMERA, a malware toolkit developed specifically for Ivanti VPN appliances.
Mandiant ... reported that attackers began leveraging this vulnerability as early as mid-December, deploying the custom Spawn malware toolkit... TeamT5 reports that the threat actor used SPAWNCHIMERA, a malware toolkit developed specifically for Ivanti VPN appliances.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes adversaries using Base64, XOR, RC4, AES, hexadecimal encoding, string encryption, code flattening, custom crypters, and other obfuscation methods to hide payloads, strings, configuration data, URLs, and scripts.
The content repeatedly describes adversaries and malware deleting files, directories, droppers, scripts, logs, archives, staged data, and other artifacts from compromised systems, e.g., 'APT29 has used SDelete to remove artifacts from victim networks' and 'Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim.'
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
The content repeatedly describes threat actors and malware using valid, stolen, forged, self-signed, or abused code-signing certificates to sign malware and appear legitimate, including examples such as AppleJeus using a valid digital signature from Sectigo, APT41 leveraging code-signing certificates, FIN7 signing Carbanak payloads, and SUNBURST being digitally signed by SolarWinds.
PHASEJAM 'has modified Ivanti Connect Secure appliances and blocks the system upgrades by altering the DSUpgrade.pm file'; SPAWNCHIMERA 'has modified the Ivanti Integrity Checker Tool to evade detection.'
The content repeatedly describes threat actors and malware disabling or modifying security tools, EDR/AV, logging, firewall rules, integrity checkers, and security settings; e.g., 'Agrius used several mechanisms to try to disable security tools' and 'BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.'
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prior SPAWN-family malware with reboot-surviving persistence; described as the predecessor/base that RESURGE extends with additional commands and expanded capabilities.
Referenced as a related malware/tool with similar SSH-tunnel C2 behavior to RESURGE; no additional functional details provided in the content.
Referenced as a malware variant whose capabilities overlap with RESURGE (e.g., surviving reboots).
SPAWNCHIMERA is a malware family delivered via exploitation of Ivanti Connect Secure vulnerabilities. Specific functionality is not detailed in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.