SPAWNCHIMERA

MITRE ATT&CK: S9024 View on attack.mitre.org

Aliases: SPAWNCHIMERA

Malware type
backdoor
Family
Malware family
Operating systems
linux, network-devices
Profile updated
2026-07-07 13:11:12

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:cn country_code:us

Context

SPAWNCHIMERA is a backdoor that supports command and control and can inject malicious components into native processes. SPAWNCHIMERA It incorporates capabilities from multiple tools within the SPAWN malware family, including SPAWNANT, SPAWNMOLE, and SPAWNSNAIL. SPAWNCHIMERA was first reported in April 2024. SPAWNCHIMERA has been observed in activity attributed to People's Republic of China (PRC) state-sponsored threat actors, including UNC5221..

Detection coverage

  • 316 Sigma rules

Malware & tools used

  • Process Discovery (attack-pattern)
  • Delay Execution (attack-pattern)
  • Web Shell (attack-pattern)
  • Hijack Execution Flow (attack-pattern)
  • Boot or Logon Initialization Scripts (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Data from Local System (attack-pattern)
  • Protocol Tunneling (attack-pattern)
  • Python (attack-pattern)
  • Dynamic Linker Hijacking (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Portable Executable Injection (attack-pattern)
  • Inter-Process Communication (attack-pattern)
  • Network Sniffing (attack-pattern)
  • Prevent Command History Logging (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • File Deletion (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Code Signing (attack-pattern)
  • Timestomp (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Mutual Exclusion (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)

Exploited vulnerabilities

  • CVE-2025-22457 (vulnerability)

Reports & references

  • cloud.google.com — Ivanti Post Exploitation Lateral Movement (report)
  • cloud.google.com — China Nexus Exploiting Critical Ivanti Vulnerability (report)
  • picussecurity.com — Unc5221 Cve 2025 22457 Ivanti Connect Secure (report)
  • cloud.google.com — Ivanti Connect Secure Vpn Zero Day (report)
  • MITRE ATT&CK — S9024 (report)
  • blogs.jpcert.or.jp — Spawnchimera (report)
  • CISA — Ar25 087A (report)

External references