UNC5266 is a China-linked threat activity cluster tracked by Mandiant for post-disclosure exploitation of Ivanti Connect Secure appliances following the January 10, 2024 disclosure of CVE-2023-46805 and CVE-2024-21887. Its intrusions have involved deployment of Bishop Fox's SLIVER implant framework, a WARPWIRE variant, and TERRIBLETEA. TERRIBLETEA is a Go-based backdoor that communicates over HTTP and supports shell execution, screen capture, keylogging, port scanning, file enumeration and downloading, SOCKS5 proxying, SSH session creation, and SQL query execution. This tooling enables interactive post-exploitation access, reconnaissance, and information collection. Malware infrastructure associated with UNC5266 has also been used by RedNovember, previously tracked as TAG100; infrastructure sharing does not establish that these clusters are the same actor. UNC5266's specific victim countries, targeted industries, and state sponsorship are not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Since the initial disclosure of CVE-2023-46805 and CVE-2024-21887 on Jan. 10, 2024... Mandiant is tracking multiple clusters of activity exploiting CVE-2023-46805, CVE-2024-21887, and CVE-2024-21893... UNC5337 is suspected to exploit CVE-2023-46805 (authentication bypass) and CVE-2024-21887 (command injection) for infecting Ivanti Connect Secure appliances.
Since the initial disclosure of CVE-2023-46805 and CVE-2024-21887 on Jan. 10, 2024... Mandiant's previous blog post details zero-day exploitation of CVE-2024-21893 and CVE-2024-21887... UNC5337 is suspected to exploit CVE-2023-46805 (authentication bypass) and CVE-2024-21887 (command injection) for infecting Ivanti Connect Secure appliances.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese activity cluster referenced as having overlapping malware infrastructure with RedNovember; no additional operations described in the content.
Chinese activity cluster referenced as having overlapping malware infrastructure with RedNovember; no additional operations described in the content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.