Attackers exploited CVE-2025-0282, an unauthenticated remote code execution vulnerability in Ivanti Connect Secure, to compromise VPN appliances and deploy malware. Ivanti disclosed the stack-based buffer overflow in January 2025 alongside CVE-2025-0283, a local authenticated privilege-escalation flaw. Both vulnerabilities also affected Policy Secure and Neurons for ZTA gateways, although Ivanti reported exploitation only against Connect Secure at disclosure. JPCERT/CC subsequently identified SPAWNCHIMERA during incident response in Japan. The implant combines updated SPAWNANT, SPAWNMOLE and SPAWNSNAIL functionality, uses UNIX domain sockets instead of localhost TCP communications, and reduces forensic traces through encoded SSH key material and removed debugging messages. It also dynamically mitigates CVE-2025-0282 inside the compromised web process, potentially blocking competing attackers or exploitation-based scanners without removing the compromise.
The UK NCSC reported exploitation cases under investigation on UK networks and urged organisations to assess affected appliances for compromise, perform a vendor-recommended factory reset before updating, and continue monitoring and threat hunting. Connect Secure release 22.7R2.5 addressed both vulnerabilities. The NCSC cautioned that Ivanti’s external Integrity Checker Tool provides only a point-in-time integrity assessment and does not scan for malware or indicators of compromise, so a clean result should not replace investigation. Darktrace separately described suspicious activity on two customer networks potentially linked to CVE-2025-0282, including unusual authentication, file transfers and internal reconnaissance; those links were not confirmed, and one case could have involved a different vulnerability. JPCERT/CC published hashes and file paths for SPAWNCHIMERA and its dropped component, SPAWNSLOTH, to support detection.

See which actors are running it and whether you're in range.
14 events from the most recent confirmed update back to the earliest known activity.
The affected device made numerous internal connections consistent with network scanning and issued DCE-RPC requests.
Darktrace began observing suspicious download activity involving DeElevate64.exe and DeElevator64.dll from 104.238.130[.]185. It considered the activity potentially related to CVE-2025-0282 but cautioned that the apparent involvement of a Veeam server could indicate exploitation of another vulnerability.
The NCSC published an alert about the Ivanti vulnerabilities and said it was investigating active exploitation affecting UK networks. It urged compromise assessments, factory resets before updating, installation of security updates, and continued monitoring and threat hunting.
By 1 PM ET on January 8, Ivanti Connect Secure version 22.7R2.5 provided patches for both vulnerabilities. Policy Secure and Neurons for ZTA remained unpatched at that time.
Ivanti disclosed an unauthenticated remote code execution vulnerability and a local privilege-escalation vulnerability affecting Connect Secure, Policy Secure, and Neurons for ZTA gateways. Ivanti reported exploitation of CVE-2025-0282 against a limited number of Connect Secure devices, with no known exploitation of the other two products at disclosure.
Darktrace first detected suspicious activity on a customer network on December 29, including unusual credentials and SMB and RDP authentication. The investigation also uncovered suspicious file transfers and internal reconnaissance, although exploitation of CVE-2025-0282 was not confirmed.
JPCERT/CC confirmed multiple incidents in Japan involving exploitation of CVE-2025-0282 beginning in late December 2024, before the vulnerability was publicly disclosed.
In January 2024, Ivanti disclosed CVE-2023-46805 and CVE-2024-21887. Attackers could chain the authentication bypass and command injection vulnerabilities to achieve unauthenticated remote code execution on vulnerable Ivanti systems.
JPCERT/CC revealed that SPAWNCHIMERA uses UNIX domain sockets, encoded SSH key material, and removed debugging messages to reduce detection opportunities, and dynamically mitigates CVE-2025-0282 inside the compromised web process. It also published hashes and observed file paths for SPAWNCHIMERA and SPAWNSLOTH.
JPCERT/CC identified SPAWNCHIMERA, an updated implant combining SPAWNANT, SPAWNMOLE, and SPAWNSNAIL functionality, while responding to Ivanti exploitation incidents. The implant also drops SPAWNSLOTH.
JPCERT/CC issued an alert concerning CVE-2025-0282 and reported that multiple attack groups were already exploiting the vulnerability.
Google reported deployment of SPAWN-family malware following exploitation of CVE-2025-0282, preceding JPCERT/CC's analysis of the updated SPAWNCHIMERA implant.
Darktrace used its Autonomous Response capability to block suspicious internal connections while preserving the device's usual connectivity. It reported that these actions halted the compromise and prevented further damage.
Following the reconnaissance in its second case, Darktrace observed successful NTLMv2 authentication using a new administrative credential and the hostname DESKTOP-1JIMIV3. The device also wrote to.bat over SMB, potentially as part of an attempt to deploy a remote scheduled task.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
darktrace.com
Open sourcerapid7.com
Open sourceblogs.jpcert.or.jp
Open sourcencsc.gov.uk
Open sourceforums.ivanti.com
Open sourcelabs.watchtowr.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.