Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC5174

Also known as: Uteus, UNC5174 by Mandiant, GOREVERSE, Mysterious Elephant, STAC6451 was published, CL-STA-0048, NosyDoor

Description

UNC5174, a Chinese state-sponsored threat actor, has been identified by Mandiant for exploiting critical vulnerabilities in F5 BIG-IP and ScreenConnect. They have been linked to targeting research and education institutions, businesses, charities, NGOs, and government organizations in Southeast Asia, the U.S., and the UK. UNC5174 is believed to have connections to China's Ministry of State Security and has been observed using custom tooling and the SUPERSHELL framework in their operations. The actor has shown indications of transitioning from hacktivist collectives to working as a contractor for Chinese intelligence agencies.

Goals & Targeting

Targeted Sectors

Government
Defense
Transportation
Critical infrastructure
Telecommunications
Manufacturing
Media
Financial services
Information technology
Maritime
Education
Retail
Aerospace
Aviation
Energy
Oil gas
Healthcare
Mining

Targeted Countries / Regions

CN
US
IN
BR
FR
AU
PL
IL
KP
CA
JP
AE
UA
IR

AI Analysis

· 1 week ago

Executive Summary

UNC5174, also known as Uteus, is a Chinese state-sponsored threat actor identified by Mandiant. They exploit critical vulnerabilities in F5 BIG-IP and ScreenConnect, targeting research, education, businesses, NGOs, and government organizations in Southeast Asia, the U.S., and the UK. Their operations suggest a transition from hacktivism to working as contractors for Chinese intelligence agencies.

Goals & Targeting

UNC5174's primary goals likely include state-sponsored espionage and intelligence gathering, aligning with China's strategic interests in Southeast Asia, the U.S., and the UK. Their targeting of research institutions and businesses may aim to acquire sensitive information or disrupt operations. The group's victims are diverse but often involve organizations that could yield valuable intelligence for national security purposes.

Enhanced Description

UNC5174 is a sophisticated Chinese state-sponsored threat group known for exploiting critical vulnerabilities in F5 BIG-IP and ScreenConnect systems. Linked to China's Ministry of State Security, Uteus targets various sectors including research and education, businesses, charities, NGOs, and government organizations across Southeast Asia, the U.S., and the UK. The group is associated with the SUPERSHELL framework and custom tooling, indicating a high level of technical prowess. Their operations suggest a shift from hacktivist activities to working as contractors for Chinese intelligence agencies, enhancing their operational sophistication.

Key Capabilities

  • Exploits critical vulnerabilities
  • Custom malware development
  • Network persistence frameworks (SUPERSHELL)
  • Lateral movement within networks

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence

ATT&CK Techniques

T1059
T1078

Software / Tooling

SUPERSHELL framework
Custom tooling

Campaigns & Victims

UNC5174's campaigns involve targeted exploitation of network infrastructure, lateral movement within victim networks, and the deployment of custom tools. Their operational tempo has been moderate, with known activity from 2023 onward. Notable operations include attacks on critical sectors, demonstrating their intent to gather intelligence.

IOC Patterns

  • Network traffic anomalies related to F5 devices
  • Known exploit signatures in network packets
  • Presence of custom malware binaries

Recommended Actions

  • Patch F5 BIG-IP and ScreenConnect vulnerabilities immediately
  • Monitor for lateral movement indicators using network logs
  • Deploy MITRE Defender rules mitigating initial access tactics
  • Conduct regular red teaming exercises focusing on critical infrastructure

Suggested Tags

APT
state-sponsored
espionage
critical-infrastructure

Confidence Assessment

Confidence in UNC5174's details is high due to Mandiant's identification, though specifics like MITRE techniques and tools are inferred rather than directly confirmed. No evident gaps beyond expected intelligence limitations.

ATT&CK Techniques

Collection
1 technique
Exfiltration
1 technique
Lateral Movement
1 technique
Privilege Escalation
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 4 IPv4 Address 6 Domain 10

References

  1. www.sentinelone.com — Cited by web research for: UNC5174 by Mandiant
  2. www.trendmicro.com — Cited by web research for: STAC6451 was published
  3. blog.talosintelligence.com — Cited by web research for: NosyDoor
  4. attack.mitre.org — Cited by web research for: Interception
  5. www.dragos.com — Cited by web research for: SYLVANITE

Intel Summary

40

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

14

Tactics

Tags

APT
Government Targeting
Hacktivism
state-sponsored
espionage
critical-infrastructure

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.