UNC5221, also tracked as UTA0178, is a China-nexus cyberespionage threat actor active since at least December 2023. The previously separate activity cluster UNC5337 was subsequently merged into UNC5221. The group targets internet-facing edge appliances to obtain access to enterprise networks, steal credentials and sensitive information, and maintain persistent access. Its victims span government, military and defense, telecommunications, technology, financial services, and industrial organizations, including aerospace, aviation, engineering, and consulting businesses. UNC5221 has repeatedly exploited Ivanti Connect Secure and Policy Secure appliances, including zero-day exploitation of CVE-2023-46805 and CVE-2024-21887 beginning in December 2023 and CVE-2025-0282 beginning in mid-December 2024. It also exploited CVE-2023-4966 against Citrix NetScaler appliances as a zero-day and CVE-2025-22457 against Ivanti appliances in March 2025. Its operations combine targeted intrusions with widespread exploitation following vulnerability disclosure. The group deploys web shells, passive backdoors, credential harvesters, and tunneling tools. Its toolset includes ZIPLINE, LIGHTWIRE, CHAINLINE, FRAMESTING, GIFTEDVISITOR, WARPWIRE, DRYHOOK, PHASEJAM, and the SPAWN malware ecosystem. SPAWN components provide persistent installation, SSH backdoor access, process injection, proxying, and log suppression. TRAILBLAZE and BRUSHFIRE provide in-memory post-exploitation capabilities. UNC5221 steals appliance configurations, account information, and session data, conducts network reconnaissance, and uses compromised accounts for lateral movement. Defense-evasion techniques include modifying integrity-checking tools and manifests, deleting logs and forensic artifacts, interfering with appliance upgrades, and routing operations through compromised network devices. UNC5221 has also been linked to the prolonged F5 intrusion discovered in August 2025, involving theft of BIG-IP source code and information about undisclosed vulnerabilities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
57 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
35 malware families attributed to this actor across reporting.
30 additional families tracked in Mallory.
21 CVEs this actor has used in observed campaigns. 21 of them exploited in the wild.
CVE-2023-46805 (an authentication bypass vulnerability) and CVE-2024-21887 (a command-injection vulnerability), when exploited in combination, allow malicious actors to achieve remote code execution (RCE) on vulnerable servers.
CVE-2024-21887 (CVSS: 9.1; Type: Command injection vulnerability). UTA0178 and UNC5221 compromises involve exploitation of CVE-2023-46805 and CVE-2024-21887 to deliver web shells and JavaScript credential harvesters to targeted CS/PS appliances.
The Bushfire exploit targets critical vulnerabilities in Ivanti's VPN appliances (CVE-2025-0282, CVE-2025-0283, and CVE-2025-22457). The Bushfire payload was recently discovered in the wild and attributed to UNC5221.
The Bushfire exploit targets critical vulnerabilities in Ivanti's VPN appliances (CVE-2025-0282, CVE-2025-0283, and CVE-2025-22457). The Bushfire payload was recently discovered in the wild and attributed to UNC5221.
Vendors additionally document KrustyLoader delivery through exploitation of specific internet-facing vulnerabilities, including the following: SAP NetWeaver (CVE-2025-31324)
16 more CVEs tied to this actor tracked in Mallory.
163 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Volexity-tracked activity cluster exploiting Ivanti Connect Secure and Policy Secure appliances to deploy web shells and JavaScript credential harvesters. The reporting characterizes the activity as likely espionage-motivated and state-linked, without identifying a sponsoring country. The content does not explicitly establish UTA0178 and UNC5221 as aliases.
A suspected China-nexus espionage group described as targeting strategically rather than opportunistically. The report tentatively attributes attacks against Ivanti appliances in late 2023 and early 2024 to UNC5221, involving exploitation of authentication-bypass and command-injection vulnerabilities to deploy Linux KrustyLoader and subsequently Sliver. The separate Windows KrustyLoader activity involving ScreenConnect is not explicitly attributed to UNC5221.
Referenced as a Chinese espionage group previously observed exploiting SAP product vulnerabilities, specifically CVE-2025-31324 affecting SAP products including SAP NetWeaver.
Mentioned as a China-linked APT group that previously exploited critical SAP flaws; not tied to the current CVE-2026-58231 exploitation in this article.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.