Target Industry
UNC5174 targets government organisations, research institutions, critical infrastructure sectors, and non-governmental organisations (NGOs).
Overview
A recent cyber espionage campaign has been linked to a Chinese state-sponsored threat actor group, UNC5174, which is also known as Uteus. The group has been observed utilising open-source tools like VShell alongside their own customised malware, Snowlight and Silver. Once the threat actors have compromised a system, it is suggested that they are reselling the access.
Impact
This campaign has a critical impact on sensitive information from government, research, and critical infrastructure sectors. This includes intellectual property, strategic plans, and confidential communications. If the compromised systems are within the government and defence sectors, it can lead to breaches in national security.
Affected Products
Linux and macOS systems are primary targets of UNC6174 along with network devices, such as routers, switches, and firewalls, especially those from vendors like Ivanti and F5, are at risk.
Exploitation
UNC5174 gains initial access to targeted systems through exploiting vulnerabilities in network appliances and using malicious scripts. As mentioned previously, they target security flaws in devices like those from Ivanti and F5.
The French National Agency for the Security of Information Systems (ANSSI) observed techniques similar to UNC5174, exploiting vulnerabilities in Ivanti Cloud Service Appliances (CSA) to gain control and execute arbitrary code during the 2024 Summer Olympics. The vulnerabilities (CVE-2024-8963, CVE-2024-9380, and CVE-2024-8190) can be weaponised to compromise these devices.
The group deploys the Snowlight malware (dropper used to install other malware) and a new in-memory backdoor called VShell1. These tools enable the threat actors to control infected machines, upload, and download files, and remain undetected for extended periods.
Containment, Mitigations & Remediations
It is highly recommended to ensure all software, especially network devices are regularly updated to patch known vulnerabilities. Deploy firewalls and Intrusion Detection/Prevention Systems to monitor and block suspicious activities. Use advanced anti-malware and endpoint detection and response (EDR) solutions to detect and remove malicious software. And implement application whitelisting to prevent unauthorised applications from executing.
Threat Landscape
F5 and Ivanti products are globally deployed in enterprise environments across various sectors, including government, healthcare, financial services, energy, and education. Organisations using Ivanti and F5 products may experience data breaches, leading to further loss of trust and potential legal actions. Additionally, organisations using these products may suffer disruption to operations due to compromised systems.
Threat Group
UNC5174 was identified as a distinct threat actor in late 2023 and is believed to be a state-sponsored group working on behalf of the Chinese government. They are known for using a combination of custom and open-source malware, and in past campaigns, they have been observed exploiting vulnerabilities in F5 BIG-IP and ScreenConnect. The group primarily targets Western countries, specifically Canada, the UK, and the US.
Further Information













