SPAWNSLOTH is a log-tampering malware component in the SPAWN ecosystem targeting Linux-based Ivanti Connect Secure VPN appliances. It conceals malicious activity by suppressing the appliance logging service, disabling local logging and remote syslog forwarding. It operates alongside the SPAWNSNAIL SSH backdoor, suppressing logging while that backdoor is active. A SPAWNSLOTH variant is also incorporated into the RESURGE implant to tamper with Ivanti device logs and obscure evidence of intrusion.
SPAWNSLOTH has been deployed in post-exploitation operations by UNC5337 and UNC5221, threat clusters associated with suspected China-nexus espionage. It was identified alongside SPAWNSNAIL, the SPAWNMOLE tunneler, and the SPAWNANT installer on compromised Ivanti appliances. Its role is defense evasion within a broader toolkit supporting covert access to enterprise edge infrastructure; backdoor, tunneling, credential-theft, and firmware-manipulation capabilities belong to companion components rather than SPAWNSLOTH itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The earliest evidence of observed CVE-2025-22457 exploitation occurred in mid-March 2025. Following successful exploitation, we observed the deployment of two newly identified malware families, the TRAILBLAZE in-memory only dropper and the BRUSHFIRE passive backdoor.
UNC5221 is a suspected China-nexus actor that Mandiant is tracking as the only group exploiting CVE-2023-46805 and CVE-2024-21887 during the pre-disclosure time frame since early Dec. 2023.
UNC5330 has been observed chaining CVE-2024-21893 and CVE-2024-21887 to compromise Ivanti Connect Secure VPN appliances as early as Feb. 2024. Post-compromise activity by UNC5330 includes deployment of PHANTOMNET and TONERJAM.
CVE-2025-0282 (CVSS: 9.0) is a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to execute arbitrary code. As per the advisory, CVE-2025-0282 has been exploited in the wild, affecting a limited number of Connect Secure devices. | The attackers also installed ‘Spawn’ tools like Spawnmole (tunneler), Spawnsnail (SSH backdoor), and Spawnsloth (log tampering utility), which, unlike the Phasejam web shell, can persist across system upgrades.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SPAWNSLOTH acts as a log tampering component tied to the SPAWNSNAIL backdoor.
UNC5337 leveraged SPAWNSLOTH as a log tampering utility.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware/tooling family referenced here as a variant used to tamper with logs on compromised systems to hinder detection and incident response.
Referenced as a malware/tool variant (liblogblock.so) used alongside RESURGE to tamper with logs on compromised Ivanti Connect Secure devices, supporting stealth and defense evasion.
A SPAWN-family log-tampering utility used to erase or manipulate Ivanti device logs to remove evidence of compromise and hinder incident response/forensics.
Log-tampering component/variant embedded within the RESURGE sample, used to interfere with Ivanti device logging.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.