Also known as: CVE-2025-0282, UNC5291, targeting U.S, IF-T, SnowSight
UNC5337 is a suspected China-nexus espionage actor that compromised Ivanti Connect Secure VPN appliances as early as Jan. 2024. UNC5337 is suspected to exploit CVE-2023-46805 (authentication bypass) and CVE-2024-21887 (command injection) for infecting Ivanti Connect Secure appliances. UNC5337 leveraged multiple custom malware families including the SPAWNSNAIL passive backdoor, SPAWNMOLE tunneler, SPAWNANT installer, and SPAWNSLOTH log tampering utility. Mandiant suspects with medium confidence that UNC5337 is UNC5221.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC5337 is a suspected China-nexus espionage actor that has compromised Ivanti Connect Secure VPN appliances since January 2024. The group is associated with medium-confidence links to UNC5221 and has demonstrated the ability to exploit specific vulnerabilities (CVE-2023-46805 and CVE-2024-21887) using a suite of custom malware tools, including SPAWNSNAIL, SPAWNMOLE, SPAWNANT, and SPAWNSLOTH. This actor's targeting of critical infrastructure suggests a focus on espionage or intelligence gathering.
Goals & Targeting
UNC5337's primary objective appears to be espionage, targeting sectors that rely on secure network communication systems, such as government agencies, critical infrastructure providers, and private enterprises. The actor’s focus on compromising VPN appliances suggests an interest in gaining unauthorized access to sensitive networks and intercepting communications. Their targeting of specific CVEs indicates a preference for vulnerabilities that allow persistence and privilege escalation, aligning with the goals of a nation-state threat group aiming to maintain long-term access to strategic systems.
Enhanced Description
UNC5337 is a cyber threat actor suspected to have ties to China-based operations, primarily focusing on espionage activities. The group has targeted Ivanti Connect Secure VPN appliances as early as January 2024, compromising these systems through the exploitation of known vulnerabilities: CVE-2023-46805 (authentication bypass) and CVE-2024-21887 (command injection). These exploits have allowed UNC5337 to deploy a range of custom malware tools, including: 1. **SPAWNNSNAIL**: A passive backdoor for long-term access. 2. **SPAWNMOLE**: A tunnelling tool likely used for establishing command and control (C2) communications. 3. **SPAWNANT**: An installer that facilitates the deployment of additional malicious payloads. 4. **SPWNSLOTH**: A utility used for log tampering, likely to erase evidence of compromise or disrupt system integrity. The actor's suspected link to UNC5221, identified with medium confidence by Mandiant, suggests a potential connection to other state-sponsored activities. While the exact operational temerity and full range of targets are unclear, UNC5337's focus on critical infrastructure such as VPN appliances indicates a strategic intent to disrupt or gather sensitive information.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC5337 has demonstrated a campaign pattern focused on compromising secure communication systems, with activity first observed in January 2024. The actor's operational tempo suggests a methodical approach, leveraging custom tools to establish persistence and exfiltrate data. While specific campaigns remain unclear, the targeting of critical infrastructure aligns with state-sponsored espionage tactics. Notable past operations include the exploitation of Ivanti Connect Secure appliances.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in identifying UNC5337 as a China-nexus espionage actor is medium, based on Mandiant's assessment. While the group’s use of specific CVEs and custom malware provides strong indicators, there is limited publicly available information to confirm its exact origins or full campaign history.
No campaigns linked yet.
No observed data linked yet.
18
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
11
Tactics