ATT&CKReferencesCISA SPAWNCHIMERA RESURGE February 2026

CISA SPAWNCHIMERA RESURGE February 2026

DHS/CISA. (2026, February 26). MAR-25993211-r1.v2 Ivanti Connect Secure (RESURGE): AR25-087A. Retrieved April 17, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareSPAWNCHIMERA

SPAWNCHIMERA has extracted the device’s Linux kernel image (vmlinux).

T1037
Boot or Logon Initialization Scripts
MalwareSPAWNCHIMERA

SPAWNCHIMERA has modified the boot process files within `/tmp/coreboot_fs/bin/init` to establish persistence.

T1055.002
Portable Executable Injection
MalwareSPAWNCHIMERA

SPAWNCHIMERA has executed only in memory and hooked itself into existing processes on the victim device to include the web process.

T1057
Process Discovery
MalwareSPAWNCHIMERA

SPAWNCHIMERA has searched for running processes to include web or dsmdm.

T1059.006
Python
MalwareSPAWNCHIMERA

SPAWNCHIMERA has searched the contents of two Python files scanner.py and scanner_legacy.py by searching for specific lines and replacing them with values that reduce their ability to track mismatches or new files.

T1070.004
File Deletion
MalwareSPAWNCHIMERA

SPAWNCHIMERA has deleted generated files and folders from victim devices.

T1070.006
Timestomp
MalwareSPAWNCHIMERA

SPAWNCHIMERA has updated the timestamp using the `touch` command.

T1505.003
Web Shell
MalwareSPAWNCHIMERA

SPAWNCHIMERA has created web shells that facilitate actions on the victim host.

T1553.002
Code Signing
MalwareSPAWNCHIMERA

SPAWNCHIMERA has generated RSA keys against modified files to sign the manifest file, so they appear legitimate.

T1572
Protocol Tunneling
MalwareSPAWNCHIMERA

SPAWNCHIMERA has created SSH tunnels to facilitate C2 communications.

T1678
Delay Execution
MalwareSPAWNCHIMERA

SPAWNCHIMERA has used delayed execution to pause for a defined interval before performing environment discovery, repeatedly checking for specific processes, such as the `dslogserver` process, prior to continuing execution.

T1685
Disable or Modify Tools
MalwareSPAWNCHIMERA

SPAWNCHIMERA has modified the Ivanti Integrity Checker Tool to evade detection.

T1690
Prevent Command History Logging
MalwareSPAWNCHIMERA

SPAWNCHIMERA has disabled logging and log forwarding on Ivanti devices targeting the `dslogserver` process.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.