UNC5174 is a China-based, China-nexus threat actor that conducts initial-access brokerage and espionage-enabling intrusions. Also tracked as CL-STA-1015, it is associated with the operator persona uetus, also spelled uteus, and closely linked to the Houken intrusion set. Its operations involve compromising internet-facing systems, maintaining persistent footholds, and monetizing or transferring access to state-sponsored groups for subsequent espionage. Direct state sponsorship has not been established. UNC5174 has targeted organizations in North America, the United Kingdom, Australia, and Southeast Asia. Closely linked Houken activity affected French government, telecommunications, media, financial, and transport organizations. UNC5174 exploits vulnerabilities in public-facing enterprise applications and appliances, including F5 BIG-IP CVE-2023-46747, GeoServer CVE-2024-36401, SAP NetWeaver CVE-2025-31324, and React Server Components CVE-2025-55182. An attributed European media intrusion exploited Ivanti Cloud Service Appliance vulnerabilities CVE-2024-8963 and CVE-2024-8190. The actor uses SNOWLIGHT to deliver VShell and Sliver, combining publicly available offensive tools with persistent remote-access capabilities. Associated Houken operations have included credential harvesting, PHP webshell deployment, modification of legitimate server-side scripts, reconnaissance, network scanning, lateral movement, email exfiltration, and Linux rootkit deployment. Operators have also patched exploited resources to prevent competing intrusions. Proxy tunnels, commercial VPNs, Tor, and operational relay infrastructure help conceal activity and support access to internal networks. SNOWLIGHT and VShell are used by multiple actors and are not exclusive attribution markers for UNC5174.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
2025年12月3日(現地時間)、React Server Components(RSC)における認証不要のリモートコード実行の脆弱性(CVE-2025-55182)が公開されました。JPCERT/CCでは、この攻撃の被害報告を複数受けています。
At the beginning of September 2024, an attacker repeatedly exploited vulnerabilities CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380 vulnerabilities to remotely execute arbitrary code on vulnerable Ivanti Cloud Service Appliance devices. These vulnerabilities were exploited as zero-days, before the publication of the Ivanti security advisory.
At the beginning of September 2024, an attacker repeatedly exploited vulnerabilities CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380 vulnerabilities to remotely execute arbitrary code on vulnerable Ivanti Cloud Service Appliance devices. These vulnerabilities were exploited as zero-days, before the publication of the Ivanti security advisory.
Google's Mandiant previously linked exploitation of a different F5 BIG-IP flaw (CVE-2023-46747) to UNC5174, an access broker assessed to be operating from China.
However, prior flaws (CVE-2025-31324) impacting SAP products, including NetWeaver, have been weaponized by China-nexus espionage clusters like UNC5221, UNC5174, and CL-STA-0048, as well as cybercrime groups such as BianLian and RansomExx. In April 2025, unknown threat actors were also observed exploiting the same critical SAP NetWeaver vulnerability to deploy a backdoor called Auto-Color.
10 more CVEs tied to this actor tracked in Mallory.
117 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An access broker previously linked to exploitation of CVE-2023-46747 in F5 BIG-IP products.
Referenced as a Chinese espionage group previously observed exploiting SAP product vulnerabilities, specifically CVE-2025-31324 affecting SAP products including SAP NetWeaver.
Mentioned as a China-linked APT group that previously exploited critical SAP flaws; not tied to the current CVE-2026-58231 exploitation in this article.
Referenced as a China-nexus espionage cluster previously observed weaponizing SAP product flaws including CVE-2025-31324.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.