UNC5673 is a PRC-nexus threat cluster associated with cyber operations targeting government sectors in South and Southeast Asia. The cluster has been observed incorporating generative AI into vulnerability research and exploit-development workflows, including integrating the Wooyun legacy vulnerability archive as a Claude code skill plugin to bias model output toward real-world bug patterns. UNC5673 has also operated middleware and relay tooling designed to aggregate access to multiple frontier AI model accounts behind a single compatible interface, including tools identified as Claude-Relay-Service and CLI-Proxy-API. This activity indicates an operational focus on scaling access to commercial AI systems for offensive research and development. Reported tradecraft includes AI-assisted vulnerability analysis and exploit development, as well as supporting infrastructure that pools and proxies multiple accounts to streamline usage. Available reporting supports a China nexus and government-sector targeting, but does not provide sufficient high-confidence detail to attribute additional capabilities, victim countries, or sub-group structure beyond the UNC5673 cluster name.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PRC-nexus threat actor referenced as using CLIProxyAPI and claude-relay-service tools associated with unauthorized API resale infrastructure.
PRC-linked cluster targeting government sectors in South and Southeast Asia and augmenting AI-assisted vulnerability research with the wooyun-legacy dataset via a Claude plugin.
Targets government sectors in South and Southeast Asia and uses a large Chinese vulnerability dataset as a Claude plugin to improve AI-assisted vulnerability reasoning.
Using AI systems for exploit development and vulnerability research.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.