Skip to main content
Mallory
8 malware familiesExploits CVEs in the wild

UNC5337

Also known asUNC5337

UNC5337 is a suspected China-linked, China-nexus cyber espionage threat actor associated with exploitation of Ivanti Connect Secure VPN appliance vulnerabilities, particularly CVE-2025-0282 as a zero-day. Reporting links UNC5337 to delivery of the SPAWN malware ecosystem, including custom Spawn malware and updated SPAWN variants, and to use of additional tools such as DRYHOOK and PHASEJAM in connection with this exploitation. Mandiant-associated reporting describes UNC5337 activity as likely part of a broader cluster tracked as UNC5221. TeamT5 and other reporting describe the activity as a widespread espionage campaign affecting organizations across 12 countries and nearly 20 industries, including automotive, chemical, government, financial institutions, and telecommunications. The actor’s tradecraft includes exploitation of edge VPN appliances for initial access and remote code execution, pivoting into internal networks, use of layered command-and-control, evasion of monitoring, and log wiping. Malware associated with the broader SPAWN ecosystem in this context includes SPAWNCHIMERA and modules such as SPAWNANT, SPAWNMOLE, SPAWNSNAIL, and SPAWNSLOTH.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • automotive
  • chemical
  • government
  • finance
  • telecommunications
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal8

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs2

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.