UNC5221 is a China-nexus cyber espionage threat cluster tracked by Mandiant and widely associated with long-term intelligence collection, edge-device exploitation, and stealthy persistence in enterprise environments. Reported aliases include UTA0178, VerdantBamboo, and WARP PANDA. UNC5221 has at times been used synonymously in public reporting with Silk Typhoon, but available reporting also notes that related clusters are not necessarily identical and should not be conflated without additional evidence. The actor is notable for repeatedly targeting internet-facing security and infrastructure appliances as an initial access vector, especially VPN gateways, firewalls, storage synchronization systems, NAS appliances, virtualization infrastructure, and other edge systems that often lack robust endpoint monitoring. UNC5221 has been linked to exploitation of multiple Ivanti vulnerabilities, including zero-day exploitation of Ivanti Connect Secure flaws such as CVE-2023-46805 and CVE-2024-21887, as well as later exploitation activity involving CVE-2025-22457 and reporting tying the group to in-the-wild exploitation of CVE-2025-4427 and CVE-2025-4428. The group has also been associated with campaigns exploiting edge and appliance technologies more broadly and with sustained targeting of VMware and similar infrastructure. UNC5221’s operations emphasize persistence, low visibility, and post-compromise access enablement. The group has maintained access in victim environments for extended periods, including intrusions lasting well over a year. Reported targeting includes government entities, defense and aerospace organizations, legal services, technology companies, IT providers, managed services providers, and organizations holding sensitive trade, legal, or national security information. Activity against law firms and technology organizations indicates an intelligence requirement extending beyond traditional government targets to entities that can provide insight into policy, trade negotiations, strategic technologies, and future operational opportunities. A defining characteristic of UNC5221 is its use of custom malware on Unix-like appliances and virtualized infrastructure. Malware and tooling publicly linked to the cluster include BRICKSTORM, a stealthy backdoor used on VMware, Linux, BSD, Windows, and appliance environments; SPAWN ecosystem components such as LIGHTWIRE, THINSPOOL, WARPWIRE, WIREFIRE, and ZIPLINE; TRAILBLAZE and BRUSHFIRE; PLENET; AGENTPSD; PhiliKit; and reporting that also links the actor to use of KrustyLoader. BRICKSTORM has been described as supporting proxying, file operations, and shell access over WebSocket-based command and control, enabling the actor to route traffic through trusted internal infrastructure. PLENET and PhiliKit have been described as passive or foothold-style backdoors aligned with the actor’s preference for durable access on systems with limited security telemetry. The group’s tradecraft includes in-memory malware deployment to reduce disk artifacts, use of legitimate third-party services to tunnel command-and-control traffic, credential harvesting, web shell deployment, modification of boot or service scripts for persistence, and abuse of trusted network positions to evade identity and access controls. In some intrusions, UNC5221 used compromised edge devices and proxy-capable malware to make cloud authentication activity appear to originate from trusted corporate infrastructure, undermining IP-based Conditional Access assumptions. The actor has also been observed re-entering environments after remediation by leveraging previously stolen credentials and retained access paths. UNC5221 is part of a broader pattern of PRC-linked intrusion activity focused on edge infrastructure and preparatory access. Reporting consistently characterizes the cluster as a sophisticated Chinese state-sponsored espionage actor with strong operational security, limited IOC reuse, and a preference for targeting systems outside normal EDR coverage. Its campaigns align with strategic intelligence collection, access operations, and theft of information relevant to national security, trade, defense, and technology development.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
33 malware families attributed to this actor across reporting.
28 additional families tracked in Mallory.
14 CVEs this actor has used in observed campaigns. 14 of them exploited in the wild.
This is an Ivanti exploit, possibly for CVE-2025-0282, CVE-2025-0283, or CVE-2025-22457 and the payload installs a backdoor. Mandiant recently discovered the payload in the wild. They attribute the activity to UNC5221, a suspected China-nexus espionage actor.
CVE-2025-22457: Stack-based buffer overflow in Connect Secure, exploited by UNC5221
We attributed nearly 30% (five vulnerabilities) of traditional espionage zero-day exploitation to PRC groups, including the exploitation of zero-day vulnerabilities in Ivanti appliances by UNC5221 (CVE-2023-46805 and CVE-2024-21887).
We attributed nearly 30% (five vulnerabilities) of traditional espionage zero-day exploitation to PRC groups, including the exploitation of zero-day vulnerabilities in Ivanti appliances by UNC5221 (CVE-2023-46805 and CVE-2024-21887).
Dell 0-Day Vulnerability A critical zero-day exploitation campaign targeting Dell RecoverPoint for Virtual Machines. The vulnerability, tracked as CVE-2026-22769, carries a maximum CVSSv3.1 score of 10.0 and has been under active exploitation since at least mid-2024.
9 more CVEs tied to this actor tracked in Mallory.
114 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-nexus espionage actor associated with BRICKSTORM intrusions targeting VMware hypervisor and Windows environments in government and IT organizations for long-term persistence and lateral movement.
Cyber-espionage campaign targeting U.S. law firms and technology organizations to steal sensitive legal, trade, and national security information, using zero-day exploitation and long-term persistence.
Chinese state-sponsored espionage group conducting long-dwell intrusions by compromising edge infrastructure and MSP environments, maintaining access through appliances such as Egnyte Storage Sync, pfSense firewalls, and Synology NAS devices, and using multiple backdoors and proxy implants to bypass controls like Microsoft 365 Conditional Access.
Chinese espionage activity involving long-term intrusions into Microsoft 365 and victim networks, compromise of an MSP, use of Brickstorm, Plenet, and AgentPSD, and exploitation of zero-day vulnerabilities in edge devices since at least 2023.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.