SPAWNANT is a custom installer component within the SPAWN malware ecosystem used in intrusions against Ivanti Connect Secure appliances and related edge environments. It has been associated with suspected China-nexus espionage activity, particularly clusters tracked as UNC5221 and UNC5337. The malware is deployed after exploitation of critical Ivanti vulnerabilities that enable unauthenticated remote code execution on exposed appliances, and it serves as a staging mechanism for additional SPAWN components and other payloads.
Within the broader framework, SPAWNANT functions as an installer for malicious payloads, enabling follow-on deployment of tooling such as SPAWNSNAIL, an SSH backdoor for persistent remote access, SPAWNMOLE, a tunneling component used to evade network defenses and reach internal systems, and SPAWNSLOTH, a log-tampering utility used to suppress local logging and remote syslog forwarding. Later reporting indicates that SPAWNWAVE evolved from SPAWNANT by combining capabilities from multiple SPAWN-family components, underscoring SPAWNANT’s role as an early modular building block in the ecosystem.
Operational use of SPAWNANT has been observed in targeted campaigns against government agencies and other sectors, as well as broader exploitation of Ivanti appliances across multiple industries and geographies. The malware is part of post-exploitation tradecraft focused on establishing footholds on edge devices, enabling persistence, facilitating follow-on access, and supporting deeper compromise of victim networks through tunneling and deployment of additional implants. High-confidence reporting supports its use on Ivanti Connect Secure appliances, which are Linux-based systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025-0282 is an unauthenticated stack-based buffer overflow vulnerability that allows remote code execution without prior authentication. Exploitation of this vulnerability has been observed in the wild since mid-December 2024. | SPAWN: A modular ecosystem consisting of: SPAWNANT: An installer for malicious payloads
UNC5337 leveraged multiple custom malware families including the SPAWNSNAIL passive backdoor, SPAWNMOLE tunneler, SPAWNANT installer, and SPAWNSLOTH log tampering utility.
UNC5337 leveraged multiple custom malware families including the SPAWNSNAIL passive backdoor, SPAWNMOLE tunneler, SPAWNANT installer, and SPAWNSLOTH log tampering utility.
It includes multiple modules with diverse capabilities: SPAWNANT: Installer
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SPAWN: A modular ecosystem consisting of: SPAWNANT: An installer for malicious payloads
UNC5337 leveraged multiple custom malware families including the SPAWNSNAIL passive backdoor, SPAWNMOLE tunneler, SPAWNANT installer, and SPAWNSLOTH log tampering utility.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware attributed to UNC5221, used in operations exploiting Ivanti zero-days against government agencies.
Custom malware used by UNC5221 in campaigns exploiting Ivanti zero-days against government agencies (functionality not described in the content).
Custom malware associated with UNC5221 activity, referenced in the context of Ivanti zero-day exploitation against government agencies.
Custom malware associated with UNC5221 activity, referenced in the context of Ivanti zero-day exploitation against government agencies.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.