Spawnant is a malware family tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed December 4, 2025; most recent activity June 17, 2026.
Spawnant is a malware family associated with the Chinese 'BrickStorm' operation described by CISA. The campaign targets VMware servers, highlighting the risk to virtualization infrastructure in enterprise networks. This underscores threat actors’ focus on hypervisors as critical footholds for lateral movement and subsequent access within organizations.
On April 3, 2025, Ivanti disclosed CVE-2025-22457, a critical buffer overflow vulnerability affecting Ivanti Connect Secure and other products. The vulnerability allows unauthenticated remote code execution, and…
A Chinese state-backed hacking group, UNC6201, has been exploiting a critical zero-day vulnerability in Dell RecoverPoint for Virtual Machines since at least mid-2024. The flaw, tracked as CVE-2026-22769, features a…
CISA, in collaboration with the NSA and Canada's Cyber Security Centre, has issued a warning about Chinese hackers using BrickStorm malware to backdoor VMware vSphere servers. The attacks primarily affect government and…