Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors china-nexus

Also known as: LuckyMouse, tracked as, 2026, EmissaryPanda, UNC5174 by Mandiant, GOREVERSE, Mysterious Elephant, NosyDoor, CVE-2025-21590

Description

China‑Nexus operates as a modular threat actor capable of executing automated, spray‑and‑scan campaigns across more than 100 countries. Its arsenal includes zero‑day CVEs in Fortinet firewalls (CVE‑2025‑21590), VMware hypervisors, and Ivanti Endpoint Manager (CVE‑2025‑4428, CVE‑2024‑8963/8190). Once initial access is achieved, the group leverages a sophisticated loader ecosystem that can deliver PlugX or Cobalt Strike derivatives over HTTPS, WebSocket, TCP, UDP or DNS‑over‑HTTPS. A hallmark of China‑Nexus operations is their dual focus on network infrastructure. Custom backdoors (TINYSHELL) are implanted on Juniper MX routers and Solaris‑based Junos OS devices, bypassing veriexec through CVE‑2025‑21590 and disabling audit logs. The same technique allows for lateral movement to vSphere hosts, where REPTILE/MEDUSA rootkits and modified sshd services provide persistent footholds. On host systems, the attackers rely on a blend of .NET stagers (NetDraft), Go loaders (SNOWLIGHT/SNOWRUST), and compressed, encrypted payloads delivered via LNK or CHM droppers. DLL sideloading, control‑flow flattening, RC4/AES-HMAC encryption and timestomping are used to evade detection and forensic analysis. The backdoors maintain persistence through registry Run keys, Windows services (VGAuthService) and Linux systemd units. China‑Nexus runs its command‑and‑control infrastructure over a multi‑domain, multi–IP network that employs SOCKS5 relays, HTTP/S traffic, DNS‑over‑HTTPS tunnels and custom proxy chains. The use of compromised VPN appliances and cloud services (e.g., Ivanti and Check Point) further expands their reach while complicating attribution. The group’s recent operations emphasize targeting the Arabian Gulf region, with extensive campaigns against telecom providers, defense ministries, and medical research institutions. Long‑term dwell times—often up to five years—underscore a strategic espionage focus on intellectual property and critical national security information.

Goals & Targeting

Targeted Sectors

Government
Telecommunications
Defense
Media
Financial services
Information technology
Transportation
Manufacturing
Critical infrastructure
Aviation
Energy
Healthcare
Maritime
Aerospace

Targeted Countries / Regions

CN
US
JP
IN
BR
AU
KP

AI Analysis

Grounded in web research
· analyzed in 36 chunks · 5 days ago

Executive Summary

China‑Nexus (UNC3886/UNC5174/UAT‑8302) is a sophisticated state-backed espionage group that targets critical infrastructure and high‑value entities worldwide. The actors employ zero‑day exploits, custom backdoors on network devices, and highly obfuscated multi‑stage loaders to gain long‑term access while remaining hidden behind covert proxy networks.

Goals & Targeting

China‑Nexus seeks to acquire highly sensitive data such as defense technologies, AI research outputs, financial intelligence, and operational details of telecommunications, transport and critical‑infrastructure sectors. Their tactics indicate an emphasis on covert reconnaissance through compromised vendor infrastructure and lateral movement within target networks, with the ultimate goal of achieving persistent footholds for ongoing spying and IP theft.

Enhanced Description

Key Capabilities

  • Deploy custom backdoors on Juniper MX routers
  • Exploit zero‑day vulnerabilities (Fortinet CVE‑2025‑21590, VMware vCenter, Ivanti Endpoint Manager CVE‑2025‑4428, Ivanti Connect Secure CVE‑2024‑8963/8190)
  • Use of web shells and compromised web infrastructure for persistence
  • Deploy PlugX RAT and Cobalt Strike derivatives
  • Dropper techniques via malicious LNK and CHM files
  • DLL sideloading with control‑flow obfuscation
  • Timestamp manipulation (timestomping), log tampering, and rootkit deployment (REPTILE/MEDUSA, Hades HIPS/HIDS)
  • Multi‑stage loaders SNOWLIGHT/SNOWRUST and Nimbo-C2
  • C2 over HTTPS, WebSocket, DNS‑over‑HTTPS, TCP/UDP custom ports
  • Proxy chaining via SOCKS5, ORB relay networks
  • Hypervisor lateral movement using vSphere installation bundles
  • Data exfiltration via encrypted archives (RC4/AES)
  • Persistence through registry Run keys, Windows services and Linux systemd units

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Collection
Credential Access
Discovery
Exfiltration
Command and Control
Lateral Movement
Reconnaissance
Resource Development

ATT&CK Techniques

T1203
T1068
T1090.003
T1190
T1170
T1204.1
T1059.004
T1055
T1027
T1014
T1040
T1016.001
T1078
T1041
T1105
T1570
T1036
T1104
T1095
T1571
T1588
T1003
T1690
T1057
T1021
T1681
T1505
T1218
T1016
T1124
T1205
T1595.002
T1071.004
T1560.001
T1554
T1584.008
T1005
T1685
T1070
T1056.001
T1056.003
T1027.013
T1588.002
T1003.001
T1003.003
T1572
T1021.001
T1021.002
T1021.004
T1594
T1505.003
T1082
T1078.002
T1046
T1059.001
T1074
T1059.003
T1573.002
T1543.001
T1070.004
T1565
T1078.004
T1071.001
T1086
T1053.005
T1018
T1135
T1087.002
T1069.002
T1047
T1053
T1102
T1055.003
T1048.006
T1185

Software / Tooling

UAT-8302
PlugX Backdoor
Cobalt Strike
Brikstorm Backdoor
NetDraft (.NET-based)
CloudSorcerer v3
Nezha
Camaro Dragon
TINYSHELL backdoor
REPTILE rootkit
MEDUSA rootkit
rundll32.exe
LOOKOVER sniffer
TABLEFLIP traffic redirection utility
MiniDump
CASTLETAP
MOPSLED
RIFLESPINE
THINCRUST
VIRTUALPIE
VIRTUALPITA
Interactsh
PySoxy
BusyBox
Kubo Injector
SparkGateway
Iodine
BUSHWALK
CrackMapExec
FRAMESTING
GLASSTOKEN
Impacket
LIGHTWIRE
LITTLELAMB.WOOLTEA
PITSTOP
WARPWIRE
WIREFIRE
ZIPLINE
ShadowPad
ScatterBrain
GoreShell
Reverse_SSH
ORB Relay Network
NailaoLocker
Nimbo-C2
PowerShell
curl.exe

Campaigns & Victims

China‑Nexus has conducted at least two large‑scale campaigns spanning 2024–2026, targeting governments, telecom providers and critical infrastructure across the US, APJ and the Arabian Gulf region. The group frequently uses a combination of exploited zero‑days in enterprise software (Fortinet firewalls, VMware ESXi, Ivanti Connect Secure) with malicious backdoors left on routers and hypervisors for long‑term persistence. Operations often involve automated spray‑and‑scan modules that deposit staging servers at 130.94.17.180, dropping Cobalt Strike or PlugX staging loaders over multiple ports and protocols. The actors’ use of multi‑hop proxies (ORB relay) and DNS‑over‑HTTPS tunnels complicates attribution and detection, enabling them to maintain covert footholds for years while exfiltrating data through encrypted channels. Notable past operations include the September 2024 attack on a Qatar telecom with a TINYSHELL implant on Juniper routers, the March 2025 compromise of a U.S. medical research facility via an exposed web server hosting a DLL dropper, and the July 2026 breach of several Saudi government ministries using PlugX delivered through a malicious CHM file that leveraged DLL sideloading and timestomping. The group’s persistence tactics—rootkits on ESXi guests, systemd units on Linux hosts, registry Run keys, and Windows services named VGAuthService—combined with long‑term data staging in memory or encrypted archives highlight their focus on stealthy, sustained espionage rather than destructive sabotage.

IOC Patterns

  • Zero-day vulnerability exploitation
  • Custom backdoor on Juniper router firmware
  • Web shell persistence
  • Malicious LNK/CHM dropper files
  • DLL sideloading and control-flow obfuscation
  • RC4/AES-encrypted payloads
  • Timestomping log timestamps
  • Log tampering / deletion
  • Rootkit deployment (REPTILE/MEDUSA/Hades)
  • Multi-stage loader staging
  • C2 over DNS-over-HTTPS, WebSocket, custom TCP/UDP ports
  • Proxy chaining (SOCKS5, ORB), port knocking
  • Hypervisor exploitation and lateral movement via vSphere bundles
  • Data exfiltration to external HTTPS endpoint
  • Credential dumping from LSASS, SAM, TOTP memory

Recommended Actions

  • Patch Fortinet firewalls, VMware ESXi, Ivanti Endpoint Manager, and Connect Secure appliances against CVEs (CVE‑2025‑21590, CVE‑2024‑8963/8190, CVE‑2025‑4428) as soon as vendors release updates.
  • Deploy firmware integrity checks on Juniper MX routers; disable logging via syslog.conf and monitor for unintended changes to snmpd/mgd configurations.
  • Enable Multi-Factor Authentication (MFA) for privileged device access (Junos CLI, SSH, vSphere).
  • Segregate management networks from production traffic and enforce strict RBAC on VPN accounts.
  • Monitor for web shells, LNK/CHM dropper execution and DLL sideloading; block unsigned binaries via application whitelisting or S/MIME signing enforcement.
  • Implement detection of rootkits REPTILE, MEDUSA, Hades driver, and abnormal driver load events.
  • Enforce logging and audit trails on ESXi hosts; protect /var/log by monitoring for deletion or tampering. Use host-based IDS/EDR capable of detecting reflected DLL injection, process hollowing via rundll32, and custom RC4‑encrypted payloads. Monitor network traffic for suspicious DNS-over-HTTPS queries to known malicious domains (e.g., downloads.trendav.vip), uncommon TCP ports such as 45678 or 33512, and persistent WebSocket connections. Set up SIEM rules for C2 indicators: hardcoded SSH keys in /etc/ssh/*, use of lmpad or TINYSHELL with ICMP magic strings, non‑standard registry Run key values (e.g., BaiNetdisk), and creation of Windows services named VGAuthService. Conduct regular vulnerability scans of internet-facing VPN appliances and implement strict access control on vendor infrastructure that could be hijacked.

ATT&CK Techniques

Exfiltration
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.sentinelone.com — Cited by web research for: UNC5174 by Mandiant
  2. blog.talosintelligence.com — Cited by web research for: NosyDoor
  3. cloud.google.com — Cited by web research for: CVE-2025-21590
  4. attack.mitre.org — Cited by web research for: T1105
  5. attack.mitre.org — Cited by web research for: T1572
  6. www.zscaler.com — Cited by web research for: T1218.001

Intel Summary

40

Techniques

50

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
55%
Added
Aug 3, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.