Malware.View on attack.mitre.org
SPAWNCHIMERA is a backdoor that supports command and control and can inject malicious components into native processes. SPAWNCHIMERA It incorporates capabilities from multiple tools within the SPAWN malware family, including SPAWNANT, SPAWNMOLE, and SPAWNSNAIL. SPAWNCHIMERA was first reported in April 2024. SPAWNCHIMERA has been observed in activity attributed to People's Republic of China (PRC) state-sponsored threat actors, including UNC5221..
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
SPAWNCHIMERA has extracted the device’s Linux kernel image (vmlinux). |
| T1027.013 Encrypted/Encoded File |
SPAWNCHIMERA has encoded a private key with XOR. SPAWNCHIMERA has also encrypted data to be extracted using AES encryption. |
| T1037 Boot or Logon Initialization Scripts |
SPAWNCHIMERA has modified the boot process files within `/tmp/coreboot_fs/bin/init` to establish persistence. |
| T1040 Network Sniffing |
SPAWNCHIMERA has monitored and filtered network traffic on compromised edge devices, allowing legitimate traffic to pass while redirecting attacker-controlled traffic to infrastructure under adversary control. |
| T1055.002 Portable Executable Injection |
SPAWNCHIMERA has executed only in memory and hooked itself into existing processes on the victim device to include the web process. |
| T1057 Process Discovery |
SPAWNCHIMERA has searched for running processes to include web or dsmdm. |
| T1059.006 Python |
SPAWNCHIMERA has searched the contents of two Python files scanner.py and scanner_legacy.py by searching for specific lines and replacing them with values that reduce their ability to track mismatches or new files. |
| T1070.004 File Deletion |
SPAWNCHIMERA has deleted generated files and folders from victim devices. |
| T1070.006 Timestomp |
SPAWNCHIMERA has updated the timestamp using the `touch` command. |
| T1082 System Information Discovery |
SPAWNCHIMERA has obtained system information such as release, uptime, and current time. |
| T1140 Deobfuscate/Decode Files or Information |
SPAWNCHIMERA has decoded a XOR encoded private key. |
| T1480.002 Mutual Exclusion |
SPAWNCHIMERA has fixed a buffer overflow vulnerability (CVE-2025-0282) by hooking the strncpy function and limiting the size to 256 to prevent other actors from leveraging the exploit. SPAWNCHIMERA has converted its process name to hexadecimal and verifies an added value which is triggered when the first byte of the source copied to the fixed strncpy function matches `0x04050203`. |
| T1505.003 Web Shell |
SPAWNCHIMERA has created web shells that facilitate actions on the victim host. |
| T1518.001 Security Software Discovery |
SPAWNCHIMERA has checked where SELinux is enabled on the targeted host. |
| T1553.002 Code Signing |
SPAWNCHIMERA has generated RSA keys against modified files to sign the manifest file, so they appear legitimate. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.