Skip to main content
Mallory
10 malware familiesExploits CVEs in the wild

UNC5174

Also known ascl_sta_1015houkenuetusUNC5174uteus

UNC5174 is a China-nexus threat actor tracked by Mandiant and others, also referred to as Uteus/Uetus, CL-STA-1015, and by ANSSI as Houken, which ANSSI suspects is operated by the same actor previously described as UNC5174. Reporting describes UNC5174 as a contractor or suspected initial access broker with ties to, or acting on behalf of, China’s Ministry of State Security (MSS), focused primarily on access operations and in some cases selling access to compromised organizations. Mandiant assessed with moderate confidence that UNC5174 is a PRC-linked actor and indicated it may be a former member of Chinese hacktivist collectives. Observed targeting includes U.S. defense contractors, U.S. and UK government entities, institutions in Asia, Western countries including the U.S., UK, and Canada, research and education institutions in Southeast Asia and the U.S., Hong Kong businesses, charities and NGOs, and think tanks in the U.S. and Taiwan. Additional reporting links Houken/UNC5174 activity in France to targeting of governmental, telecommunications, media, finance, and transport sectors via Ivanti Cloud Services Appliance zero-days. UNC5174 has also been linked to exploitation of SAP NetWeaver systems and React Server Components/Next.js environments, and to scanning and exploitation activity against internet-facing systems. Tradecraft described in the content includes aggressive exploitation of public-facing vulnerabilities, reconnaissance, web application fuzzing, vulnerability scanning, attempted theft of AWS configuration and credential files, installation of downloaders, and deployment of backdoors and remote access tooling. Vulnerabilities directly mentioned in connection with UNC5174 include CVE-2023-46747 (F5 BIG-IP TMUI), CVE-2024-1709 (ConnectWise ScreenConnect), CVE-2023-22518 (Atlassian Confluence), CVE-2022-0185 (Linux kernel), CVE-2022-30525 (Zyxel firewall), exploitation of vulnerable SAP NetWeaver systems, active exploitation of React2Shell/CVE-2025-55182, and targeting of unpatched SAP NetWeaver instances for CVE-2025-31324. NVISO also reported UNC5174 triggered exploitation of CVE-2025-41244, a VMware guest service discovery local privilege escalation vulnerability, in incident response engagements. Malware and tooling associated with UNC5174 in the provided content include SNOWLIGHT, VShell/VSHELL, Sliver, Cobalt Strike beacons, GOREVERSE/Goreverse SSH backdoor, SUPERSHELL, and AquaTunnel-related tooling noted as previously linked to UNC5174. UNC5174 has been observed using SNOWLIGHT as a stager/downloader to retrieve Sliver and VSHELL, and reporting on SAP NetWeaver exploitation specifically describes a multi-stage chain involving SNOWLIGHT, VShell, and GOREVERSE. The actor has also been linked to widespread use of VShell infrastructure, although the content notes VShell usage is not exclusive to UNC5174. Known aliases and related names directly mentioned in the content: UNC5174, Uteus, Uetus, CL-STA-1015, CLSTA1015, and Houken.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Government & Administration
  • Telecommunication Services
  • Media & Entertainment
  • Financial Services
  • Transportation

Where they target

Geographies tied to known operations.

  • 🇫🇷 France
MITRE ATT&CK

Tradecraft

18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

11 of 15 tactics20 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1595×3
Active Scanning
T1595.001
Scanning IP Blocks
T1595.002
Vulnerability Scanning
TA0001
Initial Access
1 technique
T1190×7
Exploit Public-Facing Application
TA0002
Execution
2 techniques
T1059
Command and Scripting Interpreter
T1059.004
Unix Shell
T1203×2
Exploitation for Client Execution
TA0004
Privilege Escalation
1 technique
T1068
Exploitation for Privilege Escalation
TA0005
Stealth
2 techniques
T1014
Rootkit
T1027
Obfuscated Files or Information
T1027.004
Compile After Delivery
TA0006
Credential Access
1 technique
T1552
Unsecured Credentials
T1552.001
Credentials In Files
TA0007
Discovery
1 technique
T1082
System Information Discovery
TA0008
Lateral Movement
1 technique
T1210
Exploitation of Remote Services
TA0011
Command and Control
2 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1105×4
Ingress Tool Transfer
TA0010
Exfiltration
1 technique
T1041
Exfiltration Over C2 Channel
TA0040
Impact
1 technique
T1496
Resource Hijacking
IOCS

Observables

54 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping18

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal10

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs12

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables54

Domains, IPs, and hashes tied to this actor, refreshed continuously.

UNC5174 | Mallory