DHS/CISA. (2026, February 26). MAR-25993211-r1.v2 Ivanti Connect Secure (RESURGE): AR25-087A. Retrieved April 17, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has extracted the device’s Linux kernel image (vmlinux). |
| T1037 Boot or Logon Initialization Scripts |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has modified the boot process files within `/tmp/coreboot_fs/bin/init` to establish persistence. |
| T1055.002 Portable Executable Injection |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has executed only in memory and hooked itself into existing processes on the victim device to include the web process. |
| T1057 Process Discovery |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has searched for running processes to include web or dsmdm. |
| T1059.006 Python |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has searched the contents of two Python files scanner.py and scanner_legacy.py by searching for specific lines and replacing them with values that reduce their ability to track mismatches or new files. |
| T1070.004 File Deletion |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has deleted generated files and folders from victim devices. |
| T1070.006 Timestomp |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has updated the timestamp using the `touch` command. |
| T1505.003 Web Shell |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has created web shells that facilitate actions on the victim host. |
| T1553.002 Code Signing |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has generated RSA keys against modified files to sign the manifest file, so they appear legitimate. |
| T1572 Protocol Tunneling |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has created SSH tunnels to facilitate C2 communications. |
| T1678 Delay Execution |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has used delayed execution to pause for a defined interval before performing environment discovery, repeatedly checking for specific processes, such as the `dslogserver` process, prior to continuing execution. |
| T1685 Disable or Modify Tools |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has modified the Ivanti Integrity Checker Tool to evade detection. |
| T1690 Prevent Command History Logging |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has disabled logging and log forwarding on Ivanti devices targeting the `dslogserver` process. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.