Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC5337

Also known as: CVE-2025-0282, UNC5291, targeting U.S, IF-T, SnowSight

Description

UNC5337 is a suspected China-nexus espionage actor that compromised Ivanti Connect Secure VPN appliances as early as Jan. 2024. UNC5337 is suspected to exploit CVE-2023-46805 (authentication bypass) and CVE-2024-21887 (command injection) for infecting Ivanti Connect Secure appliances. UNC5337 leveraged multiple custom malware families including the SPAWNSNAIL passive backdoor, SPAWNMOLE tunneler, SPAWNANT installer, and SPAWNSLOTH log tampering utility. Mandiant suspects with medium confidence that UNC5337 is UNC5221.

Goals & Targeting

Targeted Sectors

Financial services
Healthcare
Government
Critical infrastructure
Manufacturing
Defense
Education
Hospitality
Energy
Gaming
Telecommunications

Targeted Countries / Regions

CN
GB
IR
FR
JP
RU

AI Analysis

· 1 week ago

Executive Summary

UNC5337 is a suspected China-nexus espionage actor that has compromised Ivanti Connect Secure VPN appliances since January 2024. The group is associated with medium-confidence links to UNC5221 and has demonstrated the ability to exploit specific vulnerabilities (CVE-2023-46805 and CVE-2024-21887) using a suite of custom malware tools, including SPAWNSNAIL, SPAWNMOLE, SPAWNANT, and SPAWNSLOTH. This actor's targeting of critical infrastructure suggests a focus on espionage or intelligence gathering.

Goals & Targeting

UNC5337's primary objective appears to be espionage, targeting sectors that rely on secure network communication systems, such as government agencies, critical infrastructure providers, and private enterprises. The actor’s focus on compromising VPN appliances suggests an interest in gaining unauthorized access to sensitive networks and intercepting communications. Their targeting of specific CVEs indicates a preference for vulnerabilities that allow persistence and privilege escalation, aligning with the goals of a nation-state threat group aiming to maintain long-term access to strategic systems.

Enhanced Description

UNC5337 is a cyber threat actor suspected to have ties to China-based operations, primarily focusing on espionage activities. The group has targeted Ivanti Connect Secure VPN appliances as early as January 2024, compromising these systems through the exploitation of known vulnerabilities: CVE-2023-46805 (authentication bypass) and CVE-2024-21887 (command injection). These exploits have allowed UNC5337 to deploy a range of custom malware tools, including: 1. **SPAWNNSNAIL**: A passive backdoor for long-term access. 2. **SPAWNMOLE**: A tunnelling tool likely used for establishing command and control (C2) communications. 3. **SPAWNANT**: An installer that facilitates the deployment of additional malicious payloads. 4. **SPWNSLOTH**: A utility used for log tampering, likely to erase evidence of compromise or disrupt system integrity. The actor's suspected link to UNC5221, identified with medium confidence by Mandiant, suggests a potential connection to other state-sponsored activities. While the exact operational temerity and full range of targets are unclear, UNC5337's focus on critical infrastructure such as VPN appliances indicates a strategic intent to disrupt or gather sensitive information.

Key Capabilities

  • Exploitation of specificCVEs (e.g., CVE-2023-46805, CVE-2024-21887)
  • Deployment of custom malware families
  • Backdoor creation and persistence mechanisms
  • Command and control (C2) communication via tunnelling tools
  • Log tampering to obscure malicious activity

MITRE ATT&CK Tactics

Initial Access
Defence Evasion
Credential Access
Persistent Access
Exfiltration/Collection

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1014
T1003.001

Software / Tooling

SPAWNNSNAIL
SPAWNMOLE
SPAWNANT
SPWNSLOTH

Campaigns & Victims

UNC5337 has demonstrated a campaign pattern focused on compromising secure communication systems, with activity first observed in January 2024. The actor's operational tempo suggests a methodical approach, leveraging custom tools to establish persistence and exfiltrate data. While specific campaigns remain unclear, the targeting of critical infrastructure aligns with state-sponsored espionage tactics. Notable past operations include the exploitation of Ivanti Connect Secure appliances.

IOC Patterns

  • Spear-phishing with targeted exploits
  • Use of CVE-2023-46805 and CVE-2024-21887
  • Deployment of custom malware families like SPAWNSNAIL and SPAWNMOLE
  • Signatures related to VPN appliance compromise
  • Log tampering on compromised systems

Recommended Actions

  • Patch all systems against known CVEs (e.g., CVE-2023-46805, CVE-2024-21887)
  • Monitor for unusual activity in VPN appliances and network logs
  • Implement multi-factor authentication to mitigate authentication bypass risks
  • Conduct regular security audits of third-party software
  • Use endpoint detection and response (EDR) solutions to identify custom malware activity

Suggested Tags

APT
espionage
China-nexus
critical-infrastructure
malware

Confidence Assessment

The confidence level in identifying UNC5337 as a China-nexus espionage actor is medium, based on Mandiant's assessment. While the group’s use of specific CVEs and custom malware provides strong indicators, there is limited publicly available information to confirm its exact origins or full campaign history.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

MD5 Hash 6 Domain 10 Filename 2 IPv4 Address 2

References

  1. www.deepwatch.com — Cited by web research for: CVE-2025-0282
  2. cloud.google.com — Cited by web research for: UNC5291
  3. unit42.paloaltonetworks.com — Cited by web research for: IF-T
  4. cloud.google.com — Cited by web research for: SnowSight
  5. www.decryptiondigest.com — Cited by web research for: Langflow

Intel Summary

18

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

11

Tactics

Tags

APT
Backdoor / C2
espionage
China-nexus
critical-infrastructure
malware

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.