UNC5174 is a China-nexus threat actor assessed by multiple security vendors as an opportunistic initial access group or initial access broker with ties to the Chinese Ministry of State Security. The actor is also associated with the personas and aliases Uteus, Uetus, CL-STA-1015, and Houken; French authorities have assessed the Houken intrusion set to be operated by the same actor previously tracked as UNC5174. Reporting has also linked the persona tied to the group to former Chinese hacktivist circles, including Teng Snake, also known as Xiaoqiying or Genesis Day. UNC5174 is primarily characterized by access operations rather than exclusive ownership of downstream espionage objectives. It has been observed exploiting newly disclosed and known vulnerabilities in internet-facing systems at scale, then maintaining footholds and in some cases selling or transferring that access to other actors. Victimology has included government entities, defense contractors, research and education institutions, telecommunications, media, finance, transport, charities and NGOs, and commercial organizations across the United States, United Kingdom, Canada, France, Southeast Asia, Australia, Hong Kong, and other regions. Public reporting has specifically linked the actor to targeting Western countries and to access sales involving U.S. defense contractors, UK government entities, and Asian institutions. Tradecraft associated with UNC5174 includes aggressive exploitation of edge and web-facing technologies, reconnaissance, vulnerability scanning, web application fuzzing, credential theft attempts, persistence establishment, and use of both bespoke and open-source tooling. Publicly reported exploitation has involved products and vulnerabilities including F5 BIG-IP, ConnectWise ScreenConnect, Atlassian Confluence, Zyxel firewalls, SAP NetWeaver, Ivanti Cloud Services Appliance, React Server Components, and VMware service discovery components. In several campaigns the actor moved quickly after disclosure of high-value vulnerabilities, consistent with a role focused on obtaining footholds before follow-on exploitation. Malware and tooling linked to UNC5174 include SNOWLIGHT, a downloader or stager used to deliver payloads such as VShell and Sliver; VShell, a remote access trojan and Linux backdoor widely seen in Chinese-speaking intrusion activity; GOREVERSE, an SSH backdoor; SUPERSHELL; Cobalt Strike in some exploitation chains; and tunneling or access-enablement tooling observed in broader Chinese state-linked ecosystems. UNC5174 has also been associated with hands-on-keyboard activity such as deploying downloaders, establishing alternate access paths, and attempting to extract cloud configuration and credential material from compromised environments. The actor’s operational model appears hybrid: financially motivated access brokerage behavior overlaps with state-aligned tasking. Cisco Talos categorized UNC5174 as an opportunistic initial access group because it appears to monetize access while also supplying state-sponsored actors that conduct longer-term espionage. Mandiant and other vendors have assessed that the actor shows indications of acting as a contractor for China’s Ministry of State Security. This combination of public vulnerability exploitation, broad target acquisition, persistence tooling, and access transfer makes UNC5174 a notable example of the blurred boundary between criminal-style access operations and Chinese state-sponsored cyber espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
12 CVEs this actor has used in observed campaigns. 12 of them exploited in the wild.
On December 5, 2025, just two days after the public disclosure of CVE-2025-55182 – a maximum-severity remote code execution vulnerability in React Server Components (RSCs) – the Sysdig Threat Research Team (TRT) recovered a novel implant from a compromised Next.js application.
CVE-2025-41244 is a local privilege escalation vulnerability affecting VMware Aria Operations and VMware Tools... untrusted search path weakness (CWE-426)... actively exploited in the wild since at least mid-October 2024 by the China-linked threat actor UNC5174... Broadcom... issued patches in VMSA-2025-0015 advisory.
...exploiting bugs tracked as CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380.
...exploiting bugs tracked as CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380.
CL-STA-1015 (aka UNC5174) has a history of rapid exploitation of N-day vulnerabilities: ... CVE-2022-0185 ...
7 more CVEs tied to this actor tracked in Mallory.
56 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as prior attribution context for the SNOWLIGHT-to-VShell toolchain; not identified as the actor behind WP-SHELLSTORM in this report.
Threat cluster associated with use of the SNOWLIGHT VShell stager.
Suspected China-nexus threat actor that exploits zero-day and n-day vulnerabilities to gain access to critical infrastructure organizations in the Americas and uses SNOWLIGHT to deliver Sliver and VSHELL.
Referenced as a reported user of the SNOWLIGHT downloader observed in this incident chain following exploitation of CVE-2025-55182 (React2Shell).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.