RESURGE is a stealthy Linux implant associated with exploitation of Ivanti Connect Secure appliances, particularly in intrusions leveraging CVE-2025-0282. It is a 32-bit Linux shared-object malware component that has been characterized as a passive command-and-control implant with overlapping rootkit, bootkit, backdoor, dropper, proxying, and tunneling functionality. RESURGE is part of the broader SPAWN malware ecosystem and shares capabilities with SPAWNCHIMERA while adding distinct command behavior.
The malware is engineered for persistence and covert post-compromise access on Ivanti edge devices. It can survive reboots, establish boot-level persistence, manipulate files and integrity checks, deploy web-shell functionality, and support account creation, password resets, privilege escalation, and credential harvesting. Associated tooling observed with RESURGE includes a SPAWNSLOTH variant used for log tampering and a custom component used to extract and modify kernel and coreboot-related contents, enabling deeper persistence on compromised appliances.
A defining characteristic of RESURGE is its passive communications model. Rather than beaconing outward, it remains dormant and waits for specially crafted inbound connections, reducing network-detection opportunities. When loaded into the Ivanti web server process, it hooks network-handling functionality to inspect inbound TLS traffic, distinguish operator traffic from legitimate client traffic using a CRC32-based fingerprinting scheme, and forward non-matching traffic to the legitimate service. Operator authentication relies on forged certificate material and subsequent encrypted session establishment using elliptic-curve cryptography, allowing covert command-and-control that blends with expected appliance traffic patterns.
RESURGE has been linked to zero-day exploitation activity against Ivanti Connect Secure devices, and reporting has associated the broader intrusion activity with the China-linked threat actor UNC5221. The malware is particularly significant because it targets remote-access infrastructure that often sits at the network perimeter, making successful compromise valuable for persistence, credential access, and follow-on intrusion activity into enterprise or government environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Year Product CVE(s) Severity Exploited in the Wild CISA KEV Jan 2026 EPMM CVE-2026-1281 9.8 Yes Yes
Year Product CVE(s) Severity Exploited in the Wild CISA KEV Apr 2026 EPMM CVE-2026-1340 9.8 Yes Yes
"...installed by exploiting a zero-day vulnerability at that time, CVE-2025-0282, during attacks against organizations in Japan around December 2024..."; "CVE-2025-0282 refers to a critical security flaw in ICS that could allow unauthenticated remote code execution. It was addressed by Ivanti in early January 2025." | deliver updated versions of SPAWN called SPAWNCHIMERA and RESURGE.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SPAWNWAVE overlaps with the publicly reported SPAWNCHIMERA and RESURGE malware families.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
"The main attack vector is CVE-2025-0282, a stack-based buffer overflow vulnerability that affects Ivanti Connect Secure, Policy Secure, and ZTA Gateways."
“…web shells for credential harvesting, account creation, password resets, and escalating permissions.”
"...decrypt, modify, and re-encrypt coreboot firmware images... and manipulate filesystem contents for boot-level persistence."
"It allows RESURGE to decrypt, modify, and re-encrypt coreboot firmware images... and manipulate filesystem contents for boot-level persistence."
"the threat actor also uses a fake Ivanti certificate... the fake certificate also helps the actor evade detection by impersonating the legitimate server."
"It injects itself into the native Ivanti web server process, known as “web,” and monitors incoming TLS HELLO packets..."
"...variant of the SpawnSloth malware... Its main purpose is log tampering to hide malicious activity..."
"The implant also utilizes a variant of SpawnSloth malware (liblogblock.so) for log tampering..."
"variant of the SpawnSloth malware... Its main purpose is log tampering to hide malicious activity"
"...decrypt, modify, and re-encrypt coreboot firmware images... and manipulate filesystem contents for boot-level persistence."
"It allows RESURGE to decrypt, modify, and re-encrypt coreboot firmware images... and manipulate filesystem contents for boot-level persistence."
“Copy the web shell to the Ivanti running boot disk and manipulate the running coreboot image.”
"...RESURGE uses forged TLS certificates and a CRC32 fingerprint hashing scheme to separate ordinary traffic from attacker commands."
"...leveraging advanced cryptographic methods and forged TLS certificates to enable covert communications... monitors incoming TLS HELLO packets... CRC32 fingerprint hashing... mutual TLS authentication..."
"After fingerprint validation and authentication with the malware, the threat actor establishes secure remote access to the implant using a Mutual TLS session encrypted with the Elliptic Curve protocol."
"The implant is described as a passive command-and-control (C2) implant with rootkit, bootkit, backdoor, dropper, proxying, and tunneling capabilities."
"Instead of beaconing to the C2, it waits indefinitely for a particular inbound TLS connection..."
"BusyBox enables threat actors to perform various functions, such as download and execute payloads on compromised devices."
"...RESURGE...creates a Secure Shell (SSH) tunnel for command and control (C2)."
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stealthy malware linked to Ivanti compromise that can remain dormant within compromised environments.
A Linux shared-object implant for Ivanti Connect Secure that provides stealthy passive command-and-control by waiting for specific inbound TLS connections (rather than beaconing), includes rootkit/bootkit-like capabilities, and supports persistence and evasion (including log tampering via related tooling).
Linux shared-object implant (libdsupgrade.so) used on Ivanti Connect Secure devices. Operates as a passive C2 by hooking accept() and waiting for specific inbound TLS connections (no active beaconing). Uses CRC32-based TLS fingerprinting and a fake Ivanti certificate for authentication, then establishes mutual TLS with elliptic-curve encryption. Supports stealth/persistence via log tampering and firmware/filesystem manipulation (coreboot).
Malware deployed post-exploitation on Ivanti Connect Secure appliances; features network-level evasion, advanced cryptography, forged TLS certificates, covert comms, and can remain dormant until contacted by an operator.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.