SPAWN is a modular malware ecosystem targeting Linux-based Ivanti Connect Secure VPN appliances. Its cooperating components establish stealthy, persistent remote access and support post-exploitation operations. It is associated with UNC5221, a suspected China-nexus cyberespionage actor; activity initially tracked as UNC5337 was subsequently merged into UNC5221. SPAWN deployments have followed exploitation of Ivanti vulnerabilities, including CVE-2023-46805, CVE-2024-21887, CVE-2025-0282, and CVE-2025-22457, in intrusions affecting organizations across multiple industries and geographic regions.
The core ecosystem comprises SPAWNANT, SPAWNSNAIL, SPAWNMOLE, and SPAWNSLOTH. SPAWNANT is an installer that persistently deploys SPAWNSNAIL and SPAWNMOLE and can install additional web shells. SPAWNSNAIL provides an SSH backdoor embedded within a legitimate appliance process and can inject binaries into other processes, including additional malware into the appliance logging service. SPAWNMOLE is a C-based ELF32 tunneler that hijacks a process and hooks its communication functions to establish a proxy server. SPAWNSLOTH tampers with the logging service to suppress local logging and remote syslog forwarding, concealing backdoor activity. Together, these components provide long-term access while blending malicious functionality into legitimate appliance processes.
Additional ecosystem components include SPAWNSNARE, a Linux utility that extracts and AES-encrypts an uncompressed kernel image, and SPAWNWAVE, an evolution of SPAWNANT that combines capabilities from other SPAWN components.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The earliest evidence of observed CVE-2025-22457 exploitation occurred in mid-March 2025. Following successful exploitation, we observed the deployment of two newly identified malware families, the TRAILBLAZE in-memory only dropper and the BRUSHFIRE passive backdoor. | Additionally, deployment of the previously reported SPAWN ecosystem of malware attributed to UNC5221 was also observed.
CVE-2025-0282 is an unauthenticated stack-based buffer overflow vulnerability that allows remote code execution without prior authentication. Exploitation of this vulnerability has been observed in the wild since mid-December 2024. | Threat actors have been observed deploying multiple advanced malware families that collectively enable persistent access, facilitate data theft, and establish footholds for ongoing attacks. This includes: SPAWN: A modular ecosystem...
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The SPAWN ecosystem of malware ... includes the SPAWNANT installer, SPAWNMOLE tunneler, and the SPAWNSNAIL SSH backdoor.
The SPAWN ecosystem of malware ... includes the SPAWNANT installer, SPAWNMOLE tunneler, and the SPAWNSNAIL SSH backdoor.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware suite previously used by UNC5221 and suspected to include deployment of PhiliKit.
Malware suite used in Ivanti Connect Secure intrusions to establish persistence and support follow-on actions.
Malware ecosystem delivered via exploitation of Ivanti Connect Secure vulnerabilities; later observed in updated variants and used in campaigns attributed to China-nexus threat actors.
A previously reported malware ecosystem whose components were deployed by the threat actor in this campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.