Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC5325

Also known as: UNC5221, CVE-2024-21893, CVE-2024-21887

Description

UNC5325 is a suspected Chinese cyber espionage operator that exploited CVE-2024-21893 to compromise Ivanti Connect Secure appliances. UNC5325 leveraged code from open-source projects, installed custom malware, and modified the appliance's settings in order to evade detection and attempt to maintain persistence. UNC5325 has been observed deploying LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK. Mandiant identified TTPs and malware code overlaps in LITTLELAMB.WOOLTEA and PITHOOK with malware leveraged by UNC3886. Mandiant assesses with moderate confidence that UNC5325 is associated with UNC3886.

Goals & Targeting

Targeted Sectors

Defense
Government
Aviation
Energy
Healthcare
Maritime
Telecommunications
Financial services
Entertainment
Aerospace
Manufacturing

Targeted Countries / Regions

CN
US

AI Analysis

· 1 week ago

Executive Summary

UNC5325 is a suspected Chinese cyber espionage threat actor known for exploiting CVE-2024-21893 to compromise Ivanti Connect Secure appliances. The group has been linked to UNC3886 through TTP overlaps and malware code similarities, indicating moderate confidence in their association.

Goals & Targeting

UNC5325 appears to target government agencies and critical infrastructure sectors in China and neighboring regions for espionage purposes. Their primary objective is likely to collect sensitive information, intellectual property, or geopolitical intelligence. The choice of targets and techniques aligns closely with state-sponsored cyber espionage campaigns aiming for long-term access.

Enhanced Description

UNC5325 is a cyber espionage threat actor suspected to be based in China. First observed targeting Ivanti Connect Secure appliances in mid-2024, they exploited a zero-day vulnerability (CVE-2024-21893) and deployed custom malware. The group leverages open-source projects for their operations and employs techniques to evade detection and maintain persistence on compromised systems. Their activities include installing custom malware families such as LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK. Mandiant identified operational overlaps between UNC5325's TTPs and those of UNC3886, strengthening the likelihood that both groups are related.

Key Capabilities

  • Exploitation of zero-day vulnerabilities
  • Custom malware development deployment
  • OSINT exploitation for persistence
  • Leveraging open-source tools/frameworks

MITRE ATT&CK Tactics

Initial Access
Defense Evasion
Exfiltration

ATT&CK Techniques

T1059
T1055
T1566

Software / Tooling

LITTLELAMB.WOOLTEA
PITSTOP
PITDOG
PITJET
PITHOOK

Campaigns & Victims

UNC5325's campaign operations involve compromising network devices and appliances to establish persistent access. They have been observed conducting bulk OSINT gathering and customizing malware payloads for specific targets. Their association with UNC3886 suggests they may be part of a larger, more sophisticated APT group.

IOC Patterns

  • Exploitation of CVE-2024-21893
  • Deployment of custom malware (LITTLELAMB.WOOLTEA)
  • OSINT exploitation for persistence mechanisms
  • Network lateral movement within appliance ecosystems

Recommended Actions

  • Patch Ivanti Connect Secure appliances against CVE-2024-21893 and other known vulnerabilities.
  • Implement network monitoring focusing on LITTLELAMB.WOOLTEA and related malware signatures.
  • Conduct OSINT hygiene exercises to reduce surface attack vectors.
  • Use endpoint detection solutions for early detection of custom malware payloads.

Suggested Tags

APT
espionage
China-linked
cyber-espionage

Confidence Assessment

Moderate confidence in UNC5325's association with UNC3886 based on Mandiant findings. Further details on specific targets and TTPs are limited, affecting overall confidence.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

MD5 Hash 14 Filename 3 Domain 2 IPv4 Address 1

References

  1. apt.etda.or.th — Cited by web research for: UNC5221
  2. cloud.google.com — Cited by web research for: CVE-2024-21893
  3. attack.mitre.org — Cited by web research for: T1554
  4. attack.mitre.org — Cited by web research for: T1543

Intel Summary

30

Techniques

40

Tools

0

Campaigns

24

IOCs

0

Observed Data

12

Tactics

Tags

APT
espionage
China-linked
cyber-espionage

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.