UNC5337

First seen
2024-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:11:57

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

UNC5337 is a suspected China-nexus espionage actor that compromised Ivanti Connect Secure VPN appliances as early as Jan. 2024. UNC5337 is suspected to exploit CVE-2023-46805 (authentication bypass) and CVE-2024-21887 (command injection) for infecting Ivanti Connect Secure appliances. UNC5337 leveraged multiple custom malware families including the SPAWNSNAIL passive backdoor, SPAWNMOLE tunneler, SPAWNANT installer, and SPAWNSLOTH log tampering utility. Mandiant suspects with medium confidence that UNC5337 is UNC5221.

Exploited vulnerabilities

  • CVE-2023-46805 (vulnerability)
  • CVE-2024-21887 (vulnerability)

Related threat objects

Reports & references

  • cloud.google.com — Ivanti Post Exploitation Lateral Movement (report)

Attributed from

  • Ivanti VPN Zero-Day Exploit Activity (CVE-2025-0282) (campaign)

External references