UNC5325UNC5325

Also known as: UNC5325

Known aliases
1

Profile

UNC5325 is a suspected Chinese cyber espionage operator that exploited CVE-2024-21893 to compromise Ivanti Connect Secure appliances. UNC5325 leveraged code from open-source projects, installed custom malware, and modified the appliance's settings in order to evade detection and attempt to maintain persistence. UNC5325 has been observed deploying LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK. Mandiant identified TTPs and malware code overlaps in LITTLELAMB.WOOLTEA and PITHOOK with malware leveraged by UNC3886. Mandiant assesses with moderate confidence that UNC5325 is associated with UNC3886.

Aliases· 1

UNC5325

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
UNC5337
Actor
UNC5330
Actor
UNC3524
Actor
UNC5266
Actor
UNC5174
Actor
UNC3569
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.