UNC5174 is a China-nexus threat actor assessed by multiple vendors as operating primarily as an initial access specialist and, in some reporting, an opportunistic initial access broker or contractor aligned with the Chinese Ministry of State Security. The actor is also associated with the aliases Uteus or Uetus, CL-STA-1015, and Houken; ANSSI has assessed the Houken intrusion set to be operated by the same actor previously tracked as UNC5174. Reporting has also linked the persona tied to the cluster to earlier Chinese hacktivist circles, although UNC5174’s more recent activity is characterized by access operations in support of espionage-oriented follow-on exploitation. UNC5174 has been observed targeting organizations in North America, the United Kingdom, Canada, Australia, Southeast Asia, Hong Kong, and Europe, including government entities, defense contractors, research and education institutions, telecommunications, media, finance, transport, charities and NGOs, and other high-value public- and private-sector organizations. The actor has shown a strong preference for exploiting exposed edge and enterprise applications shortly after disclosure, and in some cases during active mass exploitation waves. Public reporting links the group to exploitation of vulnerabilities affecting products such as F5 BIG-IP, ConnectWise ScreenConnect, Atlassian Confluence, SAP NetWeaver, Ivanti Cloud Services Appliance, Zyxel appliances, VMware service discovery components, and React Server Components-based applications. Tradecraft associated with UNC5174 centers on rapid vulnerability exploitation, foothold establishment, persistence, reconnaissance, and transfer or monetization of access. The actor has used both bespoke and widely available tooling, including SUPERSHELL, SNOWLIGHT, VShell, Sliver, Cobalt Strike, and GOREVERSE, and has also been linked to AquaTunnel-related tooling overlap in broader China-nexus operations. SNOWLIGHT has repeatedly appeared as a downloader or stager in UNC5174 intrusions, often leading to deployment of VShell or other post-compromise payloads. VShell usage has been widely associated with Chinese-speaking threat activity more broadly, so its presence alone is not uniquely attributable to UNC5174, but the SNOWLIGHT-to-VShell chain has been specifically tied to this actor in multiple investigations. Observed post-compromise behavior includes creation of backdoor administrator access, deployment of remote access trojans and SSH backdoors, use of memory-resident payloads, webshell deployment, credential and cloud-configuration theft attempts, extensive reconnaissance, web application fuzzing, scanning of internet-facing systems, and selective persistence mechanisms. UNC5174 has also been associated with exploitation activity that resulted in attempted theft of cloud credentials and configuration material from compromised environments. In VMware-related incidents, the actor was linked to triggering a local privilege-escalation flaw through abuse of service discovery behavior, consistent with its pattern of opportunistic exploitation of exposed or weakly protected infrastructure. Multiple assessments describe UNC5174 as focused more on obtaining and maintaining access than on conducting the full downstream intelligence mission itself. Mandiant reported the actor attempting to sell or transfer access to compromised networks, including access involving U.S. defense contractors, UK government entities, and Asian institutions. Cisco Talos categorized UNC5174 as an opportunistic initial access group that exploits known internet-facing vulnerabilities, establishes persistence, and then monetizes or hands off access to state-sponsored operators for longer-term espionage. This operating model fits a broader pattern in the Chinese cyber ecosystem in which access operations, relay infrastructure, and follow-on exploitation may be split across specialized teams or contractors. UNC5174 has also been associated with the use of Operational Relay Box infrastructure and overlapping ORB networks seen across other China-linked actors, reinforcing assessments that the group operates within a broader contractor or shared-services ecosystem rather than as a fully isolated intrusion set. Overall, UNC5174 is best understood as a PRC-aligned access operator whose hallmark is aggressive exploitation of newly disclosed vulnerabilities, rapid deployment of lightweight staging and remote-access tooling, and provision of footholds that can support subsequent Chinese state espionage activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
12 CVEs this actor has used in observed campaigns. 12 of them exploited in the wild.
On December 5, 2025, just two days after the public disclosure of CVE-2025-55182 – a maximum-severity remote code execution vulnerability in React Server Components (RSCs) – the Sysdig Threat Research Team (TRT) recovered a novel implant from a compromised Next.js application.
CVE-2025-41244 is a local privilege escalation vulnerability affecting VMware Aria Operations and VMware Tools... untrusted search path weakness (CWE-426)... actively exploited in the wild since at least mid-October 2024 by the China-linked threat actor UNC5174... Broadcom... issued patches in VMSA-2025-0015 advisory.
...exploiting bugs tracked as CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380.
...exploiting bugs tracked as CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380.
CL-STA-1015 (aka UNC5174) has a history of rapid exploitation of N-day vulnerabilities: ... CVE-2022-0185 ...
7 more CVEs tied to this actor tracked in Mallory.
56 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an adversary associated with ORB network usage in Project ORBITAL.
Mentioned only as prior attribution context for the SNOWLIGHT-to-VShell toolchain; not identified as the actor behind WP-SHELLSTORM in this report.
Threat cluster associated with use of the SNOWLIGHT VShell stager.
Suspected China-nexus threat actor that exploits zero-day and n-day vulnerabilities to gain access to critical infrastructure organizations in the Americas and uses SNOWLIGHT to deliver Sliver and VSHELL.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.