UNC5291 is a cluster of targeted probing activity that we assess with moderate confidence is associated with UNC3236, also known publicly as Volt Typhoon. Activity for this cluster started in December 2023 focusing on Citrix Netscaler ADC and then shifted to focus on Ivanti Connect Secure devices after details were made public in mid-Jan. 2024. Probing has been observed against the academic, energy, defense, and health sectors, which aligns with past Volt Typhoon interest in critical infrastructure. In Feb. 2024, the Cybersecurity and Infrastructure Security Agency (CISA) released an advisory warning that Volt Typhoon was targeting critical infrastructure and was potentially interested in Ivanti Connect Secure devices for initial access.
Executive Summary
UNC5291 is a cyber threat cluster linked with moderate confidence to UNC3236 (Volt Typhoon), targeting critical infrastructure sectors such as academic, energy, defense, and health. Their activities involve probing for vulnerabilities in Citrix Netscaler ADC and Ivanti Connect Secure devices, with shifts in focus based on public disclosures. The group's operations align with known patterns ofVolt Typhoon, targeting critical infrastructure, suggesting potential state-sponsored activity.
Goals & Targeting
UNC5291 appears to target sectors critical to national security, such as energy, defense, and health, consistent with Volt Typhoon's known targeting patterns. Their strategic objectives likely include gathering intelligence, disrupting operations, or preparing for potential exploitation of critical infrastructure systems. The choice of targets indicates a focus on entities that, if compromised, could have significant economic or security repercussions.
Enhanced Description
UNC5291 represents a series of cyber probing activities that are assessed with moderate confidence as linked to Volt Typhoon (UNC3236). This cluster was first observed in December 2023, initially focusing on exploiting Citrix Netscaler ADC vulnerabilities, and later shifted focus to Ivanti Connect Secure devices following public disclosures in January 2024. The targeting aligns with Volt Typhoon's historical interest in critical infrastructure sectors: academic, energy, defense, and health. In February 2024, CISA issued an advisory warning of Volt Typhoon’s potential interest in Ivanti Connect Secure devices for initial access. The group's strategic focus on critical infrastructure suggests a possible state-sponsored or nation-backed actor aiming to disrupt or obtain sensitive information.
Key Capabilities
Software / Tooling
Campaigns & Victims
UNC5291's campaign patterns involve initial probing of Citrix Netscaler ADC, followed by a shift to Ivanti Connect Secure devices after mid-January 2024. The group exhibits patience and adaptability, adjusting their focus based on disclosed information. Their targeting reflects a long-term strategic interest in critical infrastructure sectors, with potential links to state-sponsored activities as seen in past Volt Typhoon operations.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The linkage to Volt Typhoon provides moderate confidence in the assessment of UNC5291's activities. However, gaps remain in understanding the full extent of their capabilities and tools.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics