SPAWNSNARE is a Linux post-exploitation utility written in C and associated with the SPAWN malware ecosystem. It extracts an uncompressed Linux kernel image into a file and encrypts it using AES, implementing these operations without relying on external command-line tools.
SPAWNSNARE has been used by UNC5221, a suspected China-nexus cyberespionage actor, during operations targeting Ivanti Connect Secure VPN appliances. It was observed alongside other SPAWN components in activity involving exploitation of CVE-2025-22457, a buffer overflow vulnerability enabling remote code execution, beginning in mid-March 2025. Its established functionality is kernel-image extraction and encryption; backdoor access, log tampering, and persistence are functions of other components in the broader ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The earliest evidence of observed CVE-2025-22457 exploitation occurred in mid-March 2025. Following successful exploitation, we observed the deployment of two newly identified malware families, the TRAILBLAZE in-memory only dropper and the BRUSHFIRE passive backdoor.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SPAWNSNARE is a utility that is written in C and targets Linux.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.