Spawnant Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
December 4, 2025
Last Seen
June 17, 2026

Spawnant is a malware family tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed December 4, 2025; most recent activity June 17, 2026.

Overview

Spawnant is a malware family associated with the Chinese 'BrickStorm' operation described by CISA. The campaign targets VMware servers, highlighting the risk to virtualization infrastructure in enterprise networks. This underscores threat actors’ focus on hypervisors as critical footholds for lateral movement and subsequent access within organizations.

Related Threat Clusters

Recent Intelligence Reports

  • China Nexus Exploiting Critical Ivanti Vulnerability — cloud.google.com · June 17, 2026
  • Chinese hackers exploiting Dell zero-day flaw since mid — Bleepingcomputer · February 17, 2026
  • CISA warns of Chinese "BrickStorm" malware attacks on VMware servers — Bleepingcomputer · December 4, 2025

CVSS v3.1 Breakdown