QuietCrabs, also tracked as UNC5221, UTA0178, and Red Dev 61, is a cyberespionage threat actor first identified in January 2024. It targets organizations internationally, including in Russia, the United States, the United Kingdom, Germany, South Korea, Taiwan, the Philippines, Iran, and the Czech Republic. Its operations emphasize rapid exploitation of internet-facing enterprise systems and prolonged access to compromised networks. The group conducts mass internet scanning to identify vulnerable servers and exploits flaws in Microsoft SharePoint and Ivanti products. Associated vulnerabilities include CVE-2025-53770 in SharePoint, CVE-2025-4427 and CVE-2025-4428 in Ivanti Endpoint Manager Mobile, CVE-2024-21887 in Ivanti Connect Secure, and CVE-2023-38035 in Ivanti Sentry. Observed campaigns exploited newly disclosed vulnerabilities within hours to a day of public exploit availability. Following compromise, QuietCrabs deploys web shells and loaders to execute KrustyLoader and Sliver command-and-control implants. Its tooling includes ASPX web shells and JSP loaders. KrustyLoader is a Rust-based loader that retrieves and decrypts payloads before injecting them into other processes. Its evasion features include control-flow flattening, encrypted payload locations, execution-environment checks, executable relocation, and deletion of the original executable. Both Windows KrustyLoader samples and Sliver payloads have been recovered from its intrusions. The group also performs post-compromise reconnaissance, including checking external network information and file-write permissions.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
In the first incident, QuietCrabs exploited CVE-2025-4427 and CVE-2025-4428 one day after Ivanti's official advisory.
In the first incident, QuietCrabs exploited CVE-2025-4427 and CVE-2025-4428 one day after Ivanti's official advisory.
In the second incident, we found traces of successful exploitation of CVE-2025-53770 within 24 hours of a working exploit being published, and failed attempts within a few hours of the first, non-working exploits appearing.
22 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
QuietCrabs is a suspected Chinese threat group conducting attacks by exploiting vulnerabilities in enterprise software to gain initial access, deploy web shells, and deliver custom loaders and implants for further compromise.
Highly opportunistic exploitation of newly published n-days (rapid PoC-to-exploitation turnaround) against Russian organizations, leveraging multiple RCEs in enterprise products.
QuietCrabs is known for cyber espionage operations, using custom malware and maintaining long dwell times within victim infrastructure.
An active cyberespionage group first identified in January 2024 and described as probably originating in Asia. It scans internet-facing servers and rapidly exploits newly disclosed vulnerabilities to establish persistence and deploy KrustyLoader, followed by Sliver implants. The investigated incidents involved Russian companies, while its reported victim geography spans multiple countries. Some researchers link it to APT27, but the article does not establish that relationship conclusively. Its overlap with Thor is assessed as likely coincidental, not evidence of collaboration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.