Also known as: UNC5221, CVE-2024-21893, CVE-2024-21887
UNC5325 is a suspected Chinese cyber espionage operator that exploited CVE-2024-21893 to compromise Ivanti Connect Secure appliances. UNC5325 leveraged code from open-source projects, installed custom malware, and modified the appliance's settings in order to evade detection and attempt to maintain persistence. UNC5325 has been observed deploying LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK. Mandiant identified TTPs and malware code overlaps in LITTLELAMB.WOOLTEA and PITHOOK with malware leveraged by UNC3886. Mandiant assesses with moderate confidence that UNC5325 is associated with UNC3886.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC5325 is a suspected Chinese cyber espionage threat actor known for exploiting CVE-2024-21893 to compromise Ivanti Connect Secure appliances. The group has been linked to UNC3886 through TTP overlaps and malware code similarities, indicating moderate confidence in their association.
Goals & Targeting
UNC5325 appears to target government agencies and critical infrastructure sectors in China and neighboring regions for espionage purposes. Their primary objective is likely to collect sensitive information, intellectual property, or geopolitical intelligence. The choice of targets and techniques aligns closely with state-sponsored cyber espionage campaigns aiming for long-term access.
Enhanced Description
UNC5325 is a cyber espionage threat actor suspected to be based in China. First observed targeting Ivanti Connect Secure appliances in mid-2024, they exploited a zero-day vulnerability (CVE-2024-21893) and deployed custom malware. The group leverages open-source projects for their operations and employs techniques to evade detection and maintain persistence on compromised systems. Their activities include installing custom malware families such as LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK. Mandiant identified operational overlaps between UNC5325's TTPs and those of UNC3886, strengthening the likelihood that both groups are related.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC5325's campaign operations involve compromising network devices and appliances to establish persistent access. They have been observed conducting bulk OSINT gathering and customizing malware payloads for specific targets. Their association with UNC3886 suggests they may be part of a larger, more sophisticated APT group.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in UNC5325's association with UNC3886 based on Mandiant findings. Further details on specific targets and TTPs are limited, affecting overall confidence.
No campaigns linked yet.
No observed data linked yet.
30
Techniques
40
Tools
0
Campaigns
24
IOCs
0
Observed Data
12
Tactics