SPAWN is a modular malware ecosystem targeting Linux-based Ivanti Connect Secure VPN appliances to establish stealthy, persistent remote access. It is associated with UNC5221, a suspected China-nexus cyberespionage actor; activity initially tracked as UNC5337 was subsequently merged into UNC5221. SPAWN deployments have followed exploitation of Ivanti vulnerabilities, including CVE-2023-46805, CVE-2024-21887, CVE-2025-0282, and CVE-2025-22457, affecting organizations across multiple countries and industries.
The original ecosystem comprises four cooperating components. SPAWNANT persistently installs other SPAWN components and can deploy additional web shells. SPAWNMOLE is a C-based ELF tunneler that hijacks a process and hooks its communications functionality to provide proxy access. SPAWNSNAIL provides an SSH backdoor and can inject binaries into other processes. SPAWNSLOTH tampers with the appliance's logging service, suppressing local logging and remote syslog forwarding to conceal malicious activity.
Later variants consolidate functionality and reduce forensic visibility. SPAWNCHIMERA combines updated installer, tunneling, and SSH-backdoor capabilities into a single implant, uses process injection, and replaces earlier local TCP communications with UNIX domain sockets. It encodes embedded SSH private-key material rather than writing it to disk and removes debugging functionality. It also hooks a memory-copy function in the compromised web process to dynamically mitigate CVE-2025-0282. SPAWNWAVE is another evolved component that combines capabilities from earlier SPAWN tools. Together, these components support covert post-exploitation access to compromised edge appliances.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
JPCERT/CC confirmed multiple incidents in Japan involving exploitation beginning in late December 2024, before disclosure. The article describes SPAWNCHIMERA infections and its ability to dynamically fix CVE-2025-0282 by hooking strncpy and limiting the copy size to 256.
The earliest evidence of observed CVE-2025-22457 exploitation occurred in mid-March 2025. Following successful exploitation, we observed the deployment of two newly identified malware families, the TRAILBLAZE in-memory only dropper and the BRUSHFIRE passive backdoor. | Additionally, deployment of the previously reported SPAWN ecosystem of malware attributed to UNC5221 was also observed.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group deploys the SPAWN malware ecosystem, purpose-built tools for persistence, tunneling, and log wiping on compromised appliances.
The SPAWN ecosystem of malware ... includes the SPAWNANT installer, SPAWNMOLE tunneler, and the SPAWNSNAIL SSH backdoor.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware suite previously used by UNC5221 and suspected to include deployment of PhiliKit.
Malware suite used in Ivanti Connect Secure intrusions to establish persistence and support follow-on actions.
Malware ecosystem deployed by UNC5221 on compromised edge appliances to maintain persistence, establish tunnels, and wipe logs. The report discusses it alongside UNC5221's repeated zero-day campaigns against Ivanti and Citrix NetScaler.
Malware ecosystem delivered via exploitation of Ivanti Connect Secure vulnerabilities; later observed in updated variants and used in campaigns attributed to China-nexus threat actors.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.