SPAWNSNAIL is a passive SSH backdoor targeting Ivanti Connect Secure VPN appliances. It provides persistent remote access and forms part of the cooperating SPAWN malware ecosystem used for stealthy, long-term access to compromised edge devices. Its capabilities include injecting specified binaries into other processes, running a local SSH backdoor within the appliance's dsmdm process, and injecting additional malware into dslogserver.
SPAWNANT persistently installs SPAWNSNAIL alongside the SPAWNMOLE tunneler and can deploy additional web shells. The associated SPAWNSLOTH component suppresses appliance logging and remote syslog forwarding, helping conceal backdoor activity. These components support post-exploitation access following compromise of vulnerable Ivanti appliances rather than constituting an independent initial-access mechanism.
SPAWNSNAIL is associated with UNC5221, a suspected China-nexus espionage actor. Its use was initially tracked under UNC5337, which was subsequently merged into UNC5221. The SPAWN ecosystem has been deployed in campaigns exploiting Ivanti Connect Secure vulnerabilities, including CVE-2023-46805, CVE-2024-21887, CVE-2025-0282, and CVE-2025-22457. Associated operations have targeted organizations across multiple countries and industry sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
UNC5330 has been observed chaining CVE-2024-21893 and CVE-2024-21887 to compromise Ivanti Connect Secure VPN appliances as early as Feb. 2024. Post-compromise activity by UNC5330 includes deployment of PHANTOMNET and TONERJAM.
Mandiant has identified zero-day exploitation of CVE-2025-0282 in the wild beginning mid-December 2024. CVE-2025-0282 is an unauthenticated stack-based buffer overflow.
UNC5221 is a suspected China-nexus actor that Mandiant is tracking as the only group exploiting CVE-2023-46805 and CVE-2024-21887 during the pre-disclosure time frame since early Dec. 2023.
It includes multiple modules with diverse capabilities: SPAWNSNAIL: SSH backdoor
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC5337 leveraged the SPAWNSNAIL passive backdoor. Mandiant also discovered the cooperating SPAWN families on an appliance compromised by UNC5221.
SPAWNSNAIL is an SSH backdoor targeting Ivanti devices. It has an ability to inject a specified binary to other process ... as well as injecting additional malware to dslogserver.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
SPAWNSNAIL is an SSH backdoor targeting Ivanti devices. It has an ability to inject a specified binary to other process, running local SSH backdoor when injected to dsmdm process, as well as injecting additional malware to dslogserver
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A SPAWNCHIMERA module that provides SSH-based backdoor access on compromised Ivanti VPN appliances for remote control and persistence.
SSH backdoor that provides persistent remote access on compromised Ivanti appliances.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.