QuietCrabs is a cyber-espionage intrusion set believed to be of Asian origin and assessed in reporting as a suspected Chinese threat actor. It has also been tracked as UTA0178 and UNC5221. The group is associated with rapid exploitation of newly disclosed vulnerabilities in internet-facing enterprise software, including Microsoft SharePoint and multiple Ivanti products, often within hours of proof-of-concept publication. Reported victimology includes organizations in Russia as well as broader global targeting across the United States, United Kingdom, Germany, South Korea, Taiwan, the Philippines, Iran, and the Czech Republic. QuietCrabs commonly uses vulnerability exploitation for initial access, followed by deployment of an ASPX web shell and a JSP loader that retrieves KrustyLoader, which in turn deploys the Sliver implant for command and control and post-compromise operations. KrustyLoader has been described as uniquely associated with this cluster. The actor is characterized by stealth and long dwell times, with reporting citing an average dwell time of 393 days. Its tradecraft and targeting are consistent with long-term intelligence collection rather than disruptive or financially motivated operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
“...as well as CVE-2025-4427 and CVE-2025-4428 in Ivanti Endpoint Manager Mobile. QuietCrabs were spotted exploiting the mentioned vulnerabilities within hours of the PoC’s publication.”
“...as well as CVE-2025-4427 and CVE-2025-4428 in Ivanti Endpoint Manager Mobile. QuietCrabs were spotted exploiting the mentioned vulnerabilities within hours of the PoC’s publication.”
“...exploitation of RCE vulnerabilities, including CVE-2025-53770 in Microsoft SharePoint...”
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
QuietCrabs is a suspected Chinese threat group conducting attacks by exploiting vulnerabilities in enterprise software to gain initial access, deploy web shells, and deliver custom loaders and implants for further compromise.
Highly opportunistic exploitation of newly published n-days (rapid PoC-to-exploitation turnaround) against Russian organizations, leveraging multiple RCEs in enterprise products.
QuietCrabs is known for cyber espionage operations, using custom malware and maintaining long dwell times within victim infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.