SPAWNCHIMERA
MITRE ATT&CK: S9024 View on attack.mitre.org
Aliases: SPAWNCHIMERA
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- linux, network-devices
- Profile updated
- 2026-07-07 13:11:12
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:cn country_code:us
Context
SPAWNCHIMERA is a backdoor that supports command and control and can inject malicious components into native processes. SPAWNCHIMERA It incorporates capabilities from multiple tools within the SPAWN malware family, including SPAWNANT, SPAWNMOLE, and SPAWNSNAIL. SPAWNCHIMERA was first reported in April 2024. SPAWNCHIMERA has been observed in activity attributed to People's Republic of China (PRC) state-sponsored threat actors, including UNC5221..
Detection coverage
- 316 Sigma rules
Malware & tools used
- Process Discovery (attack-pattern)
- Delay Execution (attack-pattern)
- Web Shell (attack-pattern)
- Hijack Execution Flow (attack-pattern)
- Boot or Logon Initialization Scripts (attack-pattern)
- Security Software Discovery (attack-pattern)
- Data from Local System (attack-pattern)
- Protocol Tunneling (attack-pattern)
- Python (attack-pattern)
- Dynamic Linker Hijacking (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Portable Executable Injection (attack-pattern)
- Inter-Process Communication (attack-pattern)
- Network Sniffing (attack-pattern)
- Prevent Command History Logging (attack-pattern)
- Non-Standard Port (attack-pattern)
- File Deletion (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Code Signing (attack-pattern)
- Timestomp (attack-pattern)
- System Information Discovery (attack-pattern)
- Mutual Exclusion (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
Exploited vulnerabilities
- CVE-2025-22457 (vulnerability)
Reports & references
- cloud.google.com — Ivanti Post Exploitation Lateral Movement (report)
- cloud.google.com — China Nexus Exploiting Critical Ivanti Vulnerability (report)
- picussecurity.com — Unc5221 Cve 2025 22457 Ivanti Connect Secure (report)
- cloud.google.com — Ivanti Connect Secure Vpn Zero Day (report)
- MITRE ATT&CK — S9024 (report)
- blogs.jpcert.or.jp — Spawnchimera (report)
- CISA — Ar25 087A (report)
External references
- mitre-attack — S9024
- CISA SPAWNCHIMERA RESURGE February 2026
- Google UNC5221 Ivanti January 2025
- Google UNC5221 Ivanti April 2025
- Google UNC5221 BRICKSTORM SPAWNCHIMERA April 2024
- Picus Security UNC5221 Ivanti May 2025
- JPCERT SPAWNCHIMERA Ivanti February 2025
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy