logo

CISA spots spawn of Spawn malware targeting Ivanti flaw

ID: a3cd0ebb-c2d3-5588-bf70-129985666395

STIX ID: report--a3cd0ebb-c2d3-5588-bf70-129985666395

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2025-04-01

Date Updated: 2026-04-26

Author: Iain Thomson

...
...

CISA has released a malware analysis for "Resurge", a strain associated with the Spawn Chimera family that exploits CVE-2025-0282 to achieve unauthenticated remote code execution against Ivanti Connect Secure, Policy Secure, and Neurons for ZTA gateways. Resurge installs web shells, bypasses integrity checks, harvests credentials, creates accounts, resets passwords, and escalates privileges; CISA and Ivanti advise factory resets, reinstalling patched firmware, and resetting all privileged and domain account passwords (including resetting krbtgt twice) to ensure remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.