UNC5174 is a China-nexus intrusion set assessed as an opportunistic initial-access group and access broker that obtains footholds in internet-facing organizations, establishes durable access, and transfers or monetizes that access for longer-term espionage operations. It is also known as CL-STA-1015 and is assessed by France’s ANSSI to likely be the same actor as the Houken intrusion set. The personas uetus and uteus have also been associated with the actor. UNC5174 has exploited vulnerabilities in public-facing appliances and web applications, including Ivanti Cloud Service Appliance, F5 BIG-IP, VMware, SAP, GeoServer, and Apache Tomcat products. It has targeted government and commercial entities, including French government, telecommunications, media, financial, and transport organizations, as well as organizations in North America, the United Kingdom, Australia, and Southeast Asia. Activity attributed to Houken also included theft of credentials from compromised edge appliances, lateral movement into internal environments, and exfiltration of a large volume of email from a South American foreign ministry. The actor uses SNOWLIGHT as a downloader or stager for payloads including VShell, Sliver, and other remote-access tooling. It has employed PHP webshells, modified legitimate server-side scripts for persistence, reverse proxies and tunnels, public offensive-security tools, and rootkit-level capabilities on Linux appliances. Its tradecraft includes reconnaissance and scanning, credential collection, internal pivoting, operational relay infrastructure, self-patching of exploited resources to exclude competing actors, and defense evasion through rootkits and other stealth mechanisms. UNC5174 activity has been linked to China-nexus espionage and access-brokering operations; occasional cryptomining and data monetization indicate supplementary profit-seeking activity, but espionage is the dominant assessed motivation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
2025年12月3日(現地時間)、React Server Components(RSC)における認証不要のリモートコード実行の脆弱性(CVE-2025-55182)が公開されました。JPCERT/CCでは、この攻撃の被害報告を複数受けています。
At the beginning of September 2024, an attacker repeatedly exploited vulnerabilities CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380 vulnerabilities to remotely execute arbitrary code on vulnerable Ivanti Cloud Service Appliance devices. These vulnerabilities were exploited as zero-days, before the publication of the Ivanti security advisory.
At the beginning of September 2024, an attacker repeatedly exploited vulnerabilities CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380 vulnerabilities to remotely execute arbitrary code on vulnerable Ivanti Cloud Service Appliance devices. These vulnerabilities were exploited as zero-days, before the publication of the Ivanti security advisory.
However, prior flaws (CVE-2025-31324) impacting SAP products, including NetWeaver, have been weaponized by China-nexus espionage clusters like UNC5221, UNC5174, and CL-STA-0048, as well as cybercrime groups such as BianLian and RansomExx. In April 2025, unknown threat actors were also observed exploiting the same critical SAP NetWeaver vulnerability to deploy a backdoor called Auto-Color.
CVE-2025-41244 is a local privilege escalation vulnerability affecting VMware Aria Operations and VMware Tools... untrusted search path weakness (CWE-426)... actively exploited in the wild since at least mid-October 2024 by the China-linked threat actor UNC5174... Broadcom... issued patches in VMSA-2025-0015 advisory.
10 more CVEs tied to this actor tracked in Mallory.
116 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a Chinese espionage group previously observed exploiting SAP product vulnerabilities, specifically CVE-2025-31324 affecting SAP products including SAP NetWeaver.
Mentioned as a China-linked APT group that previously exploited critical SAP flaws; not tied to the current CVE-2026-58231 exploitation in this article.
Referenced as a China-nexus espionage cluster previously observed weaponizing SAP product flaws including CVE-2025-31324.
Referenced as a Chinese threat actor that has weaponized VMware Tools and VMware vCenter security flaws in espionage campaigns.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.