SpawnSloth Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
February 27, 2026
Last Seen
July 29, 2026

SpawnSloth is a malware family tracked by ThreatCluster, appearing in 2 threat clusters built from 3 intelligence report mentions.

SpawnSloth is a malware family tracked across 2 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed February 27, 2026; most recent activity July 29, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • Mandiant and Google's Threat Intelligence Group documented — cloud.google.com · July 29, 2026
  • CISA warns that RESURGE malware can be dormant on Ivanti devices — Bleepingcomputer · February 27, 2026
  • New CISA guidance targets persistent RESURGE implant as Ivanti Connect Secure threat ... — Industrialcyber.Co · February 27, 2026

Frequently asked questions

What is SpawnSloth?

SpawnSloth is a malware family tracked by ThreatCluster, appearing in 2 threat clusters built from 3 intelligence report mentions.

Is SpawnSloth still active?

The most recent intelligence report mentioning SpawnSloth on ThreatCluster is dated July 29, 2026. Activity was first observed February 27, 2026, giving a tracked span from then to July 29, 2026.

What is SpawnSloth associated with?

Across ThreatCluster reporting, SpawnSloth most frequently co-occurs with Unc5221, Malware, Zero-day Exploit, China, CVE-2023-46805, among 12 tracked related entities.

What are the latest developments involving SpawnSloth?

The most significant recent cluster is “Critical Remote Code Execution Vulnerability Exploited by China-Nexus Actor” (2 articles · Updated June 17, 2026). SpawnSloth appears across 2 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on SpawnSloth?

SpawnSloth appears in 3 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown