UNC5174
UNC5174 is a China-nexus threat actor tracked by Mandiant and others, also referred to as Uteus/Uetus, CL-STA-1015, and by ANSSI as Houken, which ANSSI suspects is operated by the same actor previously described as UNC5174. Reporting describes UNC5174 as a contractor or suspected initial access broker with ties to, or acting on behalf of, China’s Ministry of State Security (MSS), focused primarily on access operations and in some cases selling access to compromised organizations. Mandiant assessed with moderate confidence that UNC5174 is a PRC-linked actor and indicated it may be a former member of Chinese hacktivist collectives. Observed targeting includes U.S. defense contractors, U.S. and UK government entities, institutions in Asia, Western countries including the U.S., UK, and Canada, research and education institutions in Southeast Asia and the U.S., Hong Kong businesses, charities and NGOs, and think tanks in the U.S. and Taiwan. Additional reporting links Houken/UNC5174 activity in France to targeting of governmental, telecommunications, media, finance, and transport sectors via Ivanti Cloud Services Appliance zero-days. UNC5174 has also been linked to exploitation of SAP NetWeaver systems and React Server Components/Next.js environments, and to scanning and exploitation activity against internet-facing systems. Tradecraft described in the content includes aggressive exploitation of public-facing vulnerabilities, reconnaissance, web application fuzzing, vulnerability scanning, attempted theft of AWS configuration and credential files, installation of downloaders, and deployment of backdoors and remote access tooling. Vulnerabilities directly mentioned in connection with UNC5174 include CVE-2023-46747 (F5 BIG-IP TMUI), CVE-2024-1709 (ConnectWise ScreenConnect), CVE-2023-22518 (Atlassian Confluence), CVE-2022-0185 (Linux kernel), CVE-2022-30525 (Zyxel firewall), exploitation of vulnerable SAP NetWeaver systems, active exploitation of React2Shell/CVE-2025-55182, and targeting of unpatched SAP NetWeaver instances for CVE-2025-31324. NVISO also reported UNC5174 triggered exploitation of CVE-2025-41244, a VMware guest service discovery local privilege escalation vulnerability, in incident response engagements. Malware and tooling associated with UNC5174 in the provided content include SNOWLIGHT, VShell/VSHELL, Sliver, Cobalt Strike beacons, GOREVERSE/Goreverse SSH backdoor, SUPERSHELL, and AquaTunnel-related tooling noted as previously linked to UNC5174. UNC5174 has been observed using SNOWLIGHT as a stager/downloader to retrieve Sliver and VSHELL, and reporting on SAP NetWeaver exploitation specifically describes a multi-stage chain involving SNOWLIGHT, VShell, and GOREVERSE. The actor has also been linked to widespread use of VShell infrastructure, although the content notes VShell usage is not exclusive to UNC5174. Known aliases and related names directly mentioned in the content: UNC5174, Uteus, Uetus, CL-STA-1015, CLSTA1015, and Houken.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
- Telecommunication Services
- Media & Entertainment
- Financial Services
- Transportation
Where they target
Geographies tied to known operations.
- 🇫🇷 France
Tradecraft
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
Associated vulnerabilities
12 CVEs this actor has used in observed campaigns. 12 of them exploited in the wild.
On December 5, 2025, just two days after the public disclosure of CVE-2025-55182 – a maximum-severity remote code execution vulnerability in React Server Components (RSCs) – the Sysdig Threat Research Team (TRT) recovered a novel implant from a compromised Next.js application.
CVE-2025-41244 is a local privilege escalation vulnerability affecting VMware Aria Operations and VMware Tools... untrusted search path weakness (CWE-426)... actively exploited in the wild since at least mid-October 2024 by the China-linked threat actor UNC5174... Broadcom... issued patches in VMSA-2025-0015 advisory.
...exploiting bugs tracked as CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380.
...exploiting bugs tracked as CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380.
CL-STA-1015 (aka UNC5174) has a history of rapid exploitation of N-day vulnerabilities: ... CVE-2022-0185 ...
7 more CVEs tied to this actor tracked in Mallory.
Observables
54 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat cluster associated with use of the SNOWLIGHT VShell stager.
Suspected China-nexus threat actor that exploits zero-day and n-day vulnerabilities to gain access to critical infrastructure organizations in the Americas and uses SNOWLIGHT to deliver Sliver and VSHELL.
Referenced as a reported user of the SNOWLIGHT downloader observed in this incident chain following exploitation of CVE-2025-55182 (React2Shell).
Referenced as a Chinese state-backed cluster previously linked to tooling (e.g., AquaTunnel or related tools) also observed in the UAT-9686 activity.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.