Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC5291

Description

UNC5291 is a cluster of targeted probing activity that we assess with moderate confidence is associated with UNC3236, also known publicly as Volt Typhoon. Activity for this cluster started in December 2023 focusing on Citrix Netscaler ADC and then shifted to focus on Ivanti Connect Secure devices after details were made public in mid-Jan. 2024. Probing has been observed against the academic, energy, defense, and health sectors, which aligns with past Volt Typhoon interest in critical infrastructure. In Feb. 2024, the Cybersecurity and Infrastructure Security Agency (CISA) released an advisory warning that Volt Typhoon was targeting critical infrastructure and was potentially interested in Ivanti Connect Secure devices for initial access.

AI Analysis

· 1 week ago

Executive Summary

UNC5291 is a cyber threat cluster linked with moderate confidence to UNC3236 (Volt Typhoon), targeting critical infrastructure sectors such as academic, energy, defense, and health. Their activities involve probing for vulnerabilities in Citrix Netscaler ADC and Ivanti Connect Secure devices, with shifts in focus based on public disclosures. The group's operations align with known patterns ofVolt Typhoon, targeting critical infrastructure, suggesting potential state-sponsored activity.

Goals & Targeting

UNC5291 appears to target sectors critical to national security, such as energy, defense, and health, consistent with Volt Typhoon's known targeting patterns. Their strategic objectives likely include gathering intelligence, disrupting operations, or preparing for potential exploitation of critical infrastructure systems. The choice of targets indicates a focus on entities that, if compromised, could have significant economic or security repercussions.

Enhanced Description

UNC5291 represents a series of cyber probing activities that are assessed with moderate confidence as linked to Volt Typhoon (UNC3236). This cluster was first observed in December 2023, initially focusing on exploiting Citrix Netscaler ADC vulnerabilities, and later shifted focus to Ivanti Connect Secure devices following public disclosures in January 2024. The targeting aligns with Volt Typhoon's historical interest in critical infrastructure sectors: academic, energy, defense, and health. In February 2024, CISA issued an advisory warning of Volt Typhoon’s potential interest in Ivanti Connect Secure devices for initial access. The group's strategic focus on critical infrastructure suggests a possible state-sponsored or nation-backed actor aiming to disrupt or obtain sensitive information.

Key Capabilities

  • Probing vulnerabilities in Citrix Netscaler ADC
  • Targeting Ivanti Connect Secure devices post-public disclosure
  • Ability to shift focus based on intelligence
  • Experience in targeting critical infrastructure

Software / Tooling

Ivanti Connect Secure exploitation tools
Radmin (potential lateral movement tool)

Campaigns & Victims

UNC5291's campaign patterns involve initial probing of Citrix Netscaler ADC, followed by a shift to Ivanti Connect Secure devices after mid-January 2024. The group exhibits patience and adaptability, adjusting their focus based on disclosed information. Their targeting reflects a long-term strategic interest in critical infrastructure sectors, with potential links to state-sponsored activities as seen in past Volt Typhoon operations.

IOC Patterns

  • Probing attempts against Citrix Netscaler ADC
  • Spear phishing emails targeting Ivanti Connect Secure devices
  • Lateral movement using known tools like Radmin

Recommended Actions

  • Patch and secure all Citrix Netscaler ADC and Ivanti Connect Secure devices immediately
  • Implement multi-factor authentication (MFA) for critical systems
  • Monitor network traffic for signs of probing activity or unauthorized access attempts
  • Conduct regular security audits on critical infrastructure systems

Suggested Tags

APT
critical-infrastructure
espionage
cyber-physical-systems

Confidence Assessment

The linkage to Volt Typhoon provides moderate confidence in the assessment of UNC5291's activities. However, gaps remain in understanding the full extent of their capabilities and tools.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
APT
critical-infrastructure
espionage
cyber-physical-systems

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.