ATT&CKSoftwareSPAWNCHIMERA

SPAWNCHIMERA

S9024

Malware.View on attack.mitre.org

About this malware

SPAWNCHIMERA is a backdoor that supports command and control and can inject malicious components into native processes. SPAWNCHIMERA It incorporates capabilities from multiple tools within the SPAWN malware family, including SPAWNANT, SPAWNMOLE, and SPAWNSNAIL. SPAWNCHIMERA was first reported in April 2024. SPAWNCHIMERA has been observed in activity attributed to People's Republic of China (PRC) state-sponsored threat actors, including UNC5221..

Techniques used23

Procedure examples23

TechniqueProcedure example
T1005
Data from Local System

SPAWNCHIMERA has extracted the device’s Linux kernel image (vmlinux).

T1027.013
Encrypted/Encoded File

SPAWNCHIMERA has encoded a private key with XOR. SPAWNCHIMERA has also encrypted data to be extracted using AES encryption.

T1037
Boot or Logon Initialization Scripts

SPAWNCHIMERA has modified the boot process files within `/tmp/coreboot_fs/bin/init` to establish persistence.

T1040
Network Sniffing

SPAWNCHIMERA has monitored and filtered network traffic on compromised edge devices, allowing legitimate traffic to pass while redirecting attacker-controlled traffic to infrastructure under adversary control.

T1055.002
Portable Executable Injection

SPAWNCHIMERA has executed only in memory and hooked itself into existing processes on the victim device to include the web process.

T1057
Process Discovery

SPAWNCHIMERA has searched for running processes to include web or dsmdm.

T1059.006
Python

SPAWNCHIMERA has searched the contents of two Python files scanner.py and scanner_legacy.py by searching for specific lines and replacing them with values that reduce their ability to track mismatches or new files.

T1070.004
File Deletion

SPAWNCHIMERA has deleted generated files and folders from victim devices.

T1070.006
Timestomp

SPAWNCHIMERA has updated the timestamp using the `touch` command.

T1082
System Information Discovery

SPAWNCHIMERA has obtained system information such as release, uptime, and current time.

T1140
Deobfuscate/Decode Files or Information

SPAWNCHIMERA has decoded a XOR encoded private key.

T1480.002
Mutual Exclusion

SPAWNCHIMERA has fixed a buffer overflow vulnerability (CVE-2025-0282) by hooking the strncpy function and limiting the size to 256 to prevent other actors from leveraging the exploit. SPAWNCHIMERA has converted its process name to hexadecimal and verifies an added value which is triggered when the first byte of the source copied to the fixed strncpy function matches `0x04050203`.

T1505.003
Web Shell

SPAWNCHIMERA has created web shells that facilitate actions on the victim host.

T1518.001
Security Software Discovery

SPAWNCHIMERA has checked where SELinux is enabled on the targeted host.

T1553.002
Code Signing

SPAWNCHIMERA has generated RSA keys against modified files to sign the manifest file, so they appear legitimate.

View all 23 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References6

  1. CISA SPAWNCHIMERA RESURGE February 2026 Open source
    DHS/CISA. (2026, February 26). MAR-25993211-r1.v2 Ivanti Connect Secure (RESURGE): AR25-087A. Retrieved April 17, 2026.
  2. Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024 Open source
    Matt Lin, Austin Larsen, John Wolfram, Ashley Pearson, Josh Murchie, Lukasz Lamparski, Joseph Pisano, Ryan Hall, Ron Craft, Shawn Crew, Billy Wong, Tyler McLellan. (2024, April 4). Cutting Edge, Part 4: Ivanti Connect Secure VPN Post-Exploitation Lateral Movement Case Studies. Retrieved April 16, 2026.
  3. Google UNC5221 Ivanti April 2025 Open source
    John Wolfram, Michael Edie, Jacob Thompson, Matt Lin, Josh Murchie. (2025, April 3). Suspected China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457). Retrieved April 13, 2026.
  4. Google UNC5221 Ivanti January 2025 Open source
    John Wolfram, Josh Murchie, Matt Lin, Daniel Ainsworth, Robert Wallace, Dimiter Andonov, Dhanesh Kizhakkinan, Jacob Thompson. (2025, January 8). Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation. Retrieved April 14, 2026.
  5. JPCERT SPAWNCHIMERA Ivanti February 2025 Open source
    Yuma Masubuchi. (2025, February 20). SPAWNCHIMERA Malware: The Chimera Spawning from Ivanti Connect Secure Vulnerability. Retrieved April 17, 2026.
  6. Picus Security UNC5221 Ivanti May 2025 Open source
    Sila Ozeren Hacioglu. (2025, May 5). UNC5221’s Latest Exploit: Weaponizing CVE-2025-22457 in Ivanti Connect Secure. Retrieved April 13, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.