SpawnSloth is a malware family tracked by ThreatCluster, appearing in 2 threat clusters built from 3 intelligence report mentions.
SpawnSloth is a malware family tracked across 2 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed February 27, 2026; most recent activity July 29, 2026.
On April 3, 2025, Ivanti disclosed CVE-2025-22457, a critical buffer overflow vulnerability affecting Ivanti Connect Secure and other products. The vulnerability allows unauthenticated remote code execution, and…
CISA has released updated findings on RESURGE, a malware implant exploiting CVE-2025-0282 to compromise Ivanti Connect Secure devices. This malware can remain undetected and utilize advanced evasion techniques for…
SpawnSloth is a malware family tracked by ThreatCluster, appearing in 2 threat clusters built from 3 intelligence report mentions.
The most recent intelligence report mentioning SpawnSloth on ThreatCluster is dated July 29, 2026. Activity was first observed February 27, 2026, giving a tracked span from then to July 29, 2026.
Across ThreatCluster reporting, SpawnSloth most frequently co-occurs with Unc5221, Malware, Zero-day Exploit, China, CVE-2023-46805, among 12 tracked related entities.
The most significant recent cluster is “Critical Remote Code Execution Vulnerability Exploited by China-Nexus Actor” (2 articles · Updated June 17, 2026). SpawnSloth appears across 2 threat clusters in total, listed above with sources.
SpawnSloth appears in 3 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.