logo

SPAWNCHIMERA Malware: The Chimera Spawning from Ivanti Connect Secure Vulnerability

ID: 72b5d3dc-7c8b-54bc-a9d7-5d6c128a0556

STIX ID: report--72b5d3dc-7c8b-54bc-a9d7-5d6c128a0556

Feed Name: JPCERT Blog

Threat Score
85/100

Date Published: 2025-02-20

Date Updated: 2026-04-19

Author: 増渕 維摩(Yuma Masubuchi)

...
...

**Executive summary:** This report analyzes SPAWNCHIMERA, an evolved variant of the SPAWN malware family actively used to exploit Ivanti Connect Secure (CVE-2025-0282); it documents new evasion and persistence features (UNIX domain socket inter-process communication, XOR-decoded embedded SSH keys, removal of debug artifacts), a runtime hook that limits strncpy to mitigate competing exploitation, and lists confirmed IoCs (file hashes and file paths).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.