SPAWNCHIMERA has extracted the device’s Linux kernel image (vmlinux).121314
tool
SPAWNCHIMERA S9024
- Type
- malware
- Platforms
- Linux, Network Devices
- Created
- 17 April 2026
- Last modified
- 23 April 2026
SPAWNCHIMERA is a backdoor that supports command and control and can inject malicious components into native processes.[1][2][3] SPAWNCHIMERA It incorporates capabilities from multiple tools within the SPAWN malware family, including SPAWNANT, SPAWNMOLE, and SPAWNSNAIL.[4][2][3] SPAWNCHIMERA was first reported in April 2024.[2] SPAWNCHIMERA has been observed in activity attributed to People's Republic of China (PRC) state-sponsored threat actors, including UNC5221..[4][5][2][6]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S9024
SPAWNCHIMERA has encoded a private key with XOR.15 SPAWNCHIMERA has also encrypted data to be extracted using AES encryption.1617
SPAWNCHIMERA has modified the boot process files within /tmp/coreboot_fs/bin/init to establish persistence.18
SPAWNCHIMERA has monitored and filtered network traffic on compromised edge devices, allowing legitimate traffic to pass while redirecting attacker-controlled traffic to infrastructure under adversary control. 1920
SPAWNCHIMERA has executed only in memory and hooked itself into existing processes on the victim device to include the web process.212223
SPAWNCHIMERA has searched for running processes to include web or dsmdm.2425
Standing S9024
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
85th percentile · 85% of 825 ATT&CK software entries have this many Enterprise techniques or fewer.
89th percentile · 89% of 825 ATT&CK software entries have this many tactics spanned or fewer.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
15th percentile · 85% of 825 ATT&CK software entries have more detection rules per technique.
Detection coverage S9024
593 distinct rules cover the 23 techniques recorded for this tool. The 603 technique-to-rule mappings resolve to 593 distinct rules, because one rule can cover several techniques. 367 Sigma · 226 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org