Skip to main content
Mallory
MalwareUsed by 2 actorsExploits 2 CVEs

SPAWNANT

SPAWNANT is a custom malware component in the SPAWN / SPAWNCHIMERA malware ecosystem used in intrusions against Ivanti Connect Secure VPN appliances. It is specifically identified as the installer module of SPAWNCHIMERA. Reporting links its use to suspected China-nexus espionage activity, including UNC5221 and related clustering around UNC5337, in campaigns exploiting Ivanti zero-day and n-day vulnerabilities such as CVE-2025-0282 and CVE-2025-22457 for remote code execution on vulnerable edge devices. The broader SPAWNCHIMERA toolkit includes modules such as SPAWNMOLE (SOCKS5 tunneler), SPAWNSNAIL (SSH backdoor), and SPAWNSLOTH (log wiper / log-tampering component), indicating that SPAWNANT functions as the installation component for a post-exploitation toolkit supporting persistence, tunneling, backdoor access, and anti-forensics on compromised Ivanti appliances. UNC5221 is described as targeting government agencies and was also associated with attacks affecting organizations across multiple countries and industries, including government, financial institutions, telecommunications, automotive, and chemical sectors. The content also states that SPAWNWAVE is an evolved version of SPAWNANT that combines capabilities from other members of the SPAWN malware ecosystem. No standalone indicators of compromise specific to SPAWNANT are provided in the content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

2 CVES
CVE-2025-22457Unauthenticated RCE in Ivanti Connect Secure, Policy Secure, and ZTA Gateways

It includes multiple modules with diverse capabilities: SPAWNANT: Installer

via security online infosecurityonline.info
CVE-2025-0282Unauthenticated RCE in Ivanti Connect Secure, Policy Secure, and Neurons for ZTA Gateway

It includes multiple modules with diverse capabilities: SPAWNANT: Installer

via security online infosecurityonline.info
THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
UNC5221

UNC5221 ... known for exploiting Ivanti zero-days to target government agencies with custom Spawnant and Zipline malware.

via bleeping computerbleepingcomputer.com
UNC5337

It includes multiple modules with diverse capabilities: SPAWNANT: Installer

via security online infosecurityonline.info
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities2

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.