UNC5174
UNC5174 is a China-nexus threat actor assessed by multiple vendors as an initial access-focused operator or contractor with ties to China’s Ministry of State Security (MSS). Known aliases include Uteus, Uetus, CL-STA-1015, and Houken; ANSSI reported with suspicion that the Houken intrusion set is operated by the same actor previously described by Mandiant as UNC5174. Cisco Talos described UNC5174 as an opportunistic initial access group, and Mandiant assessed with moderate confidence that it is a former member of Chinese hacktivist collectives using the persona Uteus. Talos further noted the persona uetus is suspected to be a former member of Teng Snake, also known as Xiaoqiying or Genesis Day. The actor appears primarily focused on obtaining and transferring access. Mandiant reported UNC5174 attempting to sell access to compromised U.S. defense contractor appliances, UK government entities, and institutions in Asia in late 2023. Talos stated that in 2023 UNC5174 targeted organizations in North America, the United Kingdom, Australia, and Southeast Asia by exploiting known internet-facing vulnerabilities and then monetized and transferred that access to state-sponsored groups that conducted longer-term espionage. Reporting also describes UNC5174 as targeting Western countries including the United States, the United Kingdom, and Canada. Observed targeting includes U.S. and UK government organizations, Southeast Asian and U.S. research and education institutions, Hong Kong businesses, charities and NGOs, and institutions in Asia. Additional reporting links UNC5174 or the related Houken intrusion set to attacks against governmental, telecommunications, media, finance, and transport sectors in France, as well as active exploitation of SAP NetWeaver and React/Next.js environments. UNC5174 has been observed exploiting multiple public-facing vulnerabilities, including CVE-2023-46747 in F5 BIG-IP TMUI, CVE-2024-1709 in ConnectWise ScreenConnect, CVE-2023-22518 in Atlassian Confluence, CVE-2022-0185 in the Linux kernel, CVE-2022-30525 in Zyxel firewalls, vulnerabilities in Ivanti Cloud Services Appliance devices used in the Houken campaign, and SAP NetWeaver flaws including CVE-2025-31324. Reporting also states UNC5174 actively exploited React2Shell (CVE-2025-55182). NVISO additionally determined with confidence during incident response that UNC5174 triggered exploitation of CVE-2025-41244, a VMware guest service discovery local privilege escalation flaw. Tradecraft includes aggressive scanning for vulnerable internet-facing systems, reconnaissance, web application fuzzing, attempted theft of AWS configuration and credential files, installation of downloaders, and use of both bespoke and open-source tooling for persistence and follow-on access. Exposed attacker bash history reportedly showed extensive reconnaissance and scanning activity against prominent universities in the U.S., Oceania, and Hong Kong, and identified think tanks in the U.S. and Taiwan as strategic targets. Malware and tooling associated with UNC5174 include SNOWLIGHT, VShell, Sliver, Goreverse, Cobalt Strike beacons, and the SUPERSHELL framework. Multiple sources state UNC5174 used SNOWLIGHT as a stager/downloader to retrieve VShell and Sliver; EclecticIQ also reported a multi-stage chain involving SNOWLIGHT, VShell, and the SSH backdoor Goreverse on SAP NetWeaver systems. Unit 42 and other reporting linked UNC5174 to deployment of Snowlight and Vshell during exploitation of React2Shell. IIJ reported observing a Windows version of SNOWLIGHT used by UNC5174 in October 2025, whereas earlier SNOWLIGHT activity had been mostly Linux-based. NVISO noted that some VShell intrusions have been publicly attributed to UNC5174, while also cautioning that VShell use is not exclusive to this actor. Overall, the available reporting consistently characterizes UNC5174 as a PRC-linked, MSS-associated access operator that exploits exposed edge and enterprise applications at scale, establishes footholds with lightweight loaders and remote access tooling, and in some cases brokers or transfers that access for downstream espionage operations.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
- 🇬🇧 United Kingdom
- 🇦🇺 Australia
Tradecraft
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
Associated vulnerabilities
12 CVEs this actor has used in observed campaigns. 12 of them exploited in the wild.
On December 5, 2025, just two days after the public disclosure of CVE-2025-55182 – a maximum-severity remote code execution vulnerability in React Server Components (RSCs) – the Sysdig Threat Research Team (TRT) recovered a novel implant from a compromised Next.js application.
CVE-2025-41244 is a local privilege escalation vulnerability affecting VMware Aria Operations and VMware Tools... untrusted search path weakness (CWE-426)... actively exploited in the wild since at least mid-October 2024 by the China-linked threat actor UNC5174... Broadcom... issued patches in VMSA-2025-0015 advisory.
...exploiting bugs tracked as CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380.
...exploiting bugs tracked as CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380.
CL-STA-1015 (aka UNC5174) has a history of rapid exploitation of N-day vulnerabilities: ... CVE-2022-0185 ...
7 more CVEs tied to this actor tracked in Mallory.
Observables
54 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat cluster associated with use of the SNOWLIGHT VShell stager.
Suspected China-nexus threat actor that exploits zero-day and n-day vulnerabilities to gain access to critical infrastructure organizations in the Americas and uses SNOWLIGHT to deliver Sliver and VSHELL.
Referenced as a reported user of the SNOWLIGHT downloader observed in this incident chain following exploitation of CVE-2025-55182 (React2Shell).
Referenced as a Chinese state-backed cluster previously linked to tooling (e.g., AquaTunnel or related tools) also observed in the UAT-9686 activity.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.