UNC5221 is a suspected China-nexus, state-sponsored espionage threat cluster also tracked as UTA0178. The cluster is associated with targeted exploitation of internet-facing enterprise infrastructure, notably Ivanti Connect Secure zero-day vulnerabilities including CVE-2023-46805, CVE-2024-21887, CVE-2024-21893, and CVE-2025-0282. It exploited the first two Ivanti vulnerabilities before their public disclosure in December 2023 and subsequently conducted broader exploitation after disclosure. UNC5337 has been assessed as potentially overlapping with or forming part of UNC5221, while UNC5221 has also been publicly associated with Silk Typhoon; the latter relationship is not conclusively established. UNC5221-linked intrusions have used web shells, custom backdoors, KrustyLoader, Sliver, and the BRICKSTORM malware family. BRICKSTORM supports persistent access, file operations, network tunneling, proxying, and command-and-control communications designed to reduce network visibility, including DNS over HTTPS, WebSockets, nested TLS, and cloud-fronted infrastructure. Documented operations include exploitation for initial access, MFA bypass, session hijacking, use of compromised privileged credentials, reconnaissance of virtualized environments, lateral movement through RDP and SMB, deployment of persistent payloads, and data staging and exfiltration. Activity linked to UNC5221 has targeted U.S. organizations and European industries considered strategically relevant to the People’s Republic of China.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
36 malware families attributed to this actor across reporting.
31 additional families tracked in Mallory.
18 CVEs this actor has used in observed campaigns. 18 of them exploited in the wild.
CVE-2023-46805 is an authentication bypass in the web component of Ivanti Connect Secure and Ivanti Policy Secure. UNC5221/UTA0178 exploited it with CVE-2024-21887 as a zero-day from at least December 3, 2023.
CVE-2024-21887 is a command-injection flaw in Ivanti Connect Secure and Ivanti Policy Secure. Together with CVE-2023-46805, it enabled unauthenticated remote code execution and was exploited as a zero-day by UNC5221/UTA0178.
CVE-2025-0282 is an unauthenticated stack-based buffer overflow vulnerability that allows remote code execution without prior authentication. Exploitation of this vulnerability has been observed in the wild since mid-December 2024.
CVE-2025-22457: Stack-based buffer overflow in Connect Secure, exploited by UNC5221
Vendors additionally document KrustyLoader delivery through exploitation of specific internet-facing vulnerabilities, including the following: SAP NetWeaver (CVE-2025-31324)
13 more CVEs tied to this actor tracked in Mallory.
144 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a Chinese espionage group previously observed exploiting SAP product vulnerabilities, specifically CVE-2025-31324 affecting SAP products including SAP NetWeaver.
Mentioned as a China-linked APT group that previously exploited critical SAP flaws; not tied to the current CVE-2026-58231 exploitation in this article.
Referenced as a China-nexus espionage cluster previously observed weaponizing SAP product flaws including CVE-2025-31324.
Chinese-linked actor using zero-day vulnerabilities in espionage-oriented operations to steal valuable information from government agencies and private companies.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.