UNC5330 is a suspected China-nexus espionage actor. Reporting describes UNC5330 exploiting Ivanti Connect Secure VPN vulnerabilities CVE-2024-21893 and CVE-2024-21887 in early 2024, and then performing domain escalation via Active Directory Certificate Services (ADCS) abuse, specifically ESC1 (certificate template misconfiguration enabling certificate-based impersonation of privileged accounts). UNC5330 has also been tentatively linked to activity involving the Grager backdoor, which uses Microsoft Graph API/OneDrive for command-and-control and was delivered via a trojanized 7-Zip installer (including a malicious DLL and Tonerjam as a launcher).
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
UNC5330 was described as a “suspected China-nexus espionage actor” that exploited Ivanti Connect Secure VPN vulnerabilities (CVE-2024-21893 and CVE-2024-21887) to compromise appliances in early 2024.
UNC5330 was described as a “suspected China-nexus espionage actor” that exploited Ivanti Connect Secure VPN vulnerabilities (CVE-2024-21893 and CVE-2024-21887) to compromise appliances in early 2024.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reportedly chained exploitation of Ivanti vulnerabilities with subsequent ADCS ESC1 abuse to escalate privileges to domain-level control.
Suspected China-nexus espionage actor tentatively linked to the Grager activity chain via shared Tonerjam launcher artifacts; known for exploiting Ivanti Connect Secure VPN vulnerabilities in early 2024.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.