SPAWNSNARE

Malware type
exploit-kit
Profile updated
2026-07-07 14:30:10

Targeted industries: technology-and-telecommunications government-and-public-sector

Context

According to Mandiant, this is a utility that is written in C and targets Linux. It can be used to extract the uncompressed linux kernel image (vmlinux) into a file and encrypt it using AES without the need for any command line tools.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.Spawnsnare (report)
  • cloud.google.com — China Nexus Exploiting Critical Ivanti Vulnerability (report)

External references