Also known as: Uteus, UNC5174 by Mandiant, GOREVERSE, Mysterious Elephant, STAC6451 was published, CL-STA-0048, NosyDoor
UNC5174, a Chinese state-sponsored threat actor, has been identified by Mandiant for exploiting critical vulnerabilities in F5 BIG-IP and ScreenConnect. They have been linked to targeting research and education institutions, businesses, charities, NGOs, and government organizations in Southeast Asia, the U.S., and the UK. UNC5174 is believed to have connections to China's Ministry of State Security and has been observed using custom tooling and the SUPERSHELL framework in their operations. The actor has shown indications of transitioning from hacktivist collectives to working as a contractor for Chinese intelligence agencies.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC5174, also known as Uteus, is a Chinese state-sponsored threat actor identified by Mandiant. They exploit critical vulnerabilities in F5 BIG-IP and ScreenConnect, targeting research, education, businesses, NGOs, and government organizations in Southeast Asia, the U.S., and the UK. Their operations suggest a transition from hacktivism to working as contractors for Chinese intelligence agencies.
Goals & Targeting
UNC5174's primary goals likely include state-sponsored espionage and intelligence gathering, aligning with China's strategic interests in Southeast Asia, the U.S., and the UK. Their targeting of research institutions and businesses may aim to acquire sensitive information or disrupt operations. The group's victims are diverse but often involve organizations that could yield valuable intelligence for national security purposes.
Enhanced Description
UNC5174 is a sophisticated Chinese state-sponsored threat group known for exploiting critical vulnerabilities in F5 BIG-IP and ScreenConnect systems. Linked to China's Ministry of State Security, Uteus targets various sectors including research and education, businesses, charities, NGOs, and government organizations across Southeast Asia, the U.S., and the UK. The group is associated with the SUPERSHELL framework and custom tooling, indicating a high level of technical prowess. Their operations suggest a shift from hacktivist activities to working as contractors for Chinese intelligence agencies, enhancing their operational sophistication.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC5174's campaigns involve targeted exploitation of network infrastructure, lateral movement within victim networks, and the deployment of custom tools. Their operational tempo has been moderate, with known activity from 2023 onward. Notable operations include attacks on critical sectors, demonstrating their intent to gather intelligence.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in UNC5174's details is high due to Mandiant's identification, though specifics like MITRE techniques and tools are inferred rather than directly confirmed. No evident gaps beyond expected intelligence limitations.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
14
Tactics