UNC5174 is a China-nexus threat actor assessed to operate as an opportunistic initial access group and contractor aligned with the Chinese Ministry of State Security. The actor is also tracked as Uteus, Uetus, CL-STA-1015, and Houken, with reporting linking the Uteus persona to former Chinese hacktivist circles. UNC5174 appears primarily focused on obtaining footholds in victim environments through rapid exploitation of internet-facing vulnerabilities and then monetizing or transferring that access to downstream state-sponsored operators for longer-term espionage activity. UNC5174 has been observed targeting organizations in North America, the United Kingdom, Canada, Australia, Southeast Asia, Hong Kong, and Europe. Confirmed victim sectors include government, military and defense contractors, research and education institutions, media organizations, information technology and logistics firms, businesses, and charities or NGOs. Reported activity includes attempts to sell access to U.S. defense contractors, UK government entities, and Asian institutions, reinforcing its role as an access-focused operator rather than a purely end-objective espionage team. Tradecraft associated with UNC5174 centers on exploitation of known vulnerabilities in edge and web-facing systems, aggressive scanning and reconnaissance, web application fuzzing, and deployment of lightweight post-compromise tooling for persistence and handoff. Public reporting links the actor to exploitation of vulnerabilities affecting products such as F5 BIG-IP, ConnectWise ScreenConnect, Atlassian Confluence, Zyxel appliances, SAP NetWeaver, and other exposed services. In multiple campaigns, UNC5174 used the SNOWLIGHT downloader or stager to deliver payloads including VShell, Sliver, and GOREVERSE, and has also been associated with SUPERSHELL and use of Operational Relay Box infrastructure to obscure origin and relay operations. Reporting also ties the actor to theft of cloud configuration and credential material in some intrusions. UNC5174 has been implicated in exploitation waves that followed public disclosure of critical vulnerabilities, including broad opportunistic activity against exposed systems. The actor has been linked to intrusions against Western targets and to campaigns in which access was later leveraged by other China-aligned operators. This combination of vulnerability exploitation at scale, access brokerage, shared tooling, and overlap with broader Chinese espionage ecosystems distinguishes UNC5174 as a hybrid access operator supporting state objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
12 CVEs this actor has used in observed campaigns. 12 of them exploited in the wild.
On December 5, 2025, just two days after the public disclosure of CVE-2025-55182 – a maximum-severity remote code execution vulnerability in React Server Components (RSCs) – the Sysdig Threat Research Team (TRT) recovered a novel implant from a compromised Next.js application.
the attack on a European media organization was attributed to UNC5174, which exploited CVE-2024-8963 and CVE-2024-8190 to establish an initial foothold.
the attack on a European media organization was attributed to UNC5174, which exploited CVE-2024-8963 and CVE-2024-8190 to establish an initial foothold.
CVE-2025-41244 is a local privilege escalation vulnerability affecting VMware Aria Operations and VMware Tools... untrusted search path weakness (CWE-426)... actively exploited in the wild since at least mid-October 2024 by the China-linked threat actor UNC5174... Broadcom... issued patches in VMSA-2025-0015 advisory.
CL-STA-1015 (aka UNC5174) has a history of rapid exploitation of N-day vulnerabilities: ... CVE-2022-0185 ...
7 more CVEs tied to this actor tracked in Mallory.
58 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an adversary associated with ORB network usage in Project ORBITAL.
Mentioned only as prior attribution context for the SNOWLIGHT-to-VShell toolchain; not identified as the actor behind WP-SHELLSTORM in this report.
Threat cluster associated with use of the SNOWLIGHT VShell stager.
Suspected China-nexus threat actor that exploits zero-day and n-day vulnerabilities to gain access to critical infrastructure organizations in the Americas and uses SNOWLIGHT to deliver Sliver and VSHELL.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.