UNC5174
UTEUS (FORUM ALIAS)
Threat IntelligenceAPTJanuary 10, 202615 min read

UNC5174: Threat Intelligence Profile

Chinese threat actor blending espionage with cybercrime, exploiting Ivanti, F5, and Atlassian vulnerabilities using open-source C2 frameworks to target defense and research institutions.

Scroll

UNC5174 / Chinese eCrime-Espionage (also known as UNC5174, uteus (forum alias)) is a state-sponsored advanced persistent threat group attributed to China, active since 2024. The group primarily targets US/UK defense, research institutions, Asian governments sectors.

Overview & Attribution

Chinese threat actor blending espionage with cybercrime, exploiting Ivanti, F5, and Atlassian vulnerabilities using open-source C2 frameworks to target defense and research institutions.

Threat Assessment

UNC5174 has been active since 2024, attributed to China. The group is known for targeting US/UK defense, research institutions, Asian governments using a combination of custom malware, living-off-the-land techniques, and sophisticated social engineering.

Arsenal & Tools

UNC5174 employs a diverse arsenal of custom and shared tooling:

Targeting & Operations

The group focuses on US/UK defense, research institutions, Asian governments sectors, with operations spanning multiple geographic regions. Their campaigns typically involve carefully crafted spearphishing, strategic watering holes, and exploitation of public-facing applications.

Operational Pattern

UNC5174 is characterized by persistent, long-term access operations. Once inside a target network, the group establishes multiple redundant persistence mechanisms and moves laterally to high-value systems before beginning data exfiltration.

MITRE ATT&CK Mapping

TacticTechniqueUsage
Initial AccessT1190 Exploit Public-Facing AppIvanti/F5/Confluence zero-days
ExecutionT1059.004 Unix ShellBash-based payloads
PersistenceT1053.003 CronCron job persistence
Defense EvasionT1036 MasqueradingOpen-source tool disguise
C2T1572 Protocol TunnelingVShell/Sliver tunneling
C2T1071.001 Web ProtocolsHTTPS C2

Notable Campaigns

UNC5174 has been linked to multiple significant campaigns targeting US/UK defense, research institutions, Asian governments organizations. The group continuously evolves its tooling and infrastructure to evade detection while maintaining persistent access to compromised networks.

Detection & Defense

Defend Against UNC5174

Mjolnir Security provides specialized capabilities to detect and respond to UNC5174 operations.

APT DetectionThreat HuntingIncident ResponseMDR ServicesThreat Intelligence
  • APT Threat Hunting Proactive hunting for UNC5174 TTPs, tooling artifacts, and infrastructure indicators within your environment.
  • Threat Intelligence Continuous monitoring of UNC5174 campaigns and infrastructure changes with actionable intelligence for your defense team.
  • 24/7 Incident Response Rapid containment and forensic investigation. Call +1 833 403 5875.
Written by: Mjolnir Security  |  Published: January 10, 2026