UTA0178
Aliases: UNC5221, Red Dev 61
- First seen
- 2021-05-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Last IoC activity
- 2026-06-08 12:56:46
- Profile updated
- 2026-07-07 11:48:41
Targeted industries: government-and-public-sector technology-and-telecommunications energy-and-utilities
Targeted regions: country_code:us country_code:uk country_code:au
Context
While Volexity largely observed the attacker essentially living off the land, they still deployed a handful of malware files and tools during the course of the incident which primarily consisted of webshells, proxy utilities, and file modifications to allow credential harvesting. Once UTA0178 had access into the network via the ICS VPN appliance, their general approach was to pivot from system to system using compromised credentials. They would then further compromise credentials of users on any new system that was breached, and use these credentials to log into additional systems via RDP. Volexity observed the attacker obtaining credentials in a variety of ways.
Related threat objects
- UNC5337 (threat-actor)
Reports & references
- bsi.bund.de — Aktive Apt Gruppen Node (report)
- volexity.com — Active Exploitation Of Two Zero Day Vulnerabilities In Ivanti Connect Secure Vpn (report)
- rewterz.com — Rewterz Threat Advisory Ivanti Vpn Zero Days Weaponized By Unc5221 Threat Actors To Deploy Multiple Malware Families Active Iocs (report)
- Mandiant — Suspected Apt Targets Ivanti Zero Day (report)
- quointelligence.eu — Unc5221 Unreported And Undetected Wirefire Web Shell Variant (report)
- volexity.com — Ivanti Connect Secure Vpn Exploitation New Observations (report)
- Mandiant — Investigating Ivanti Zero Day Exploitation (report)
- cloud.google.com — Ivanti Post Exploitation Lateral Movement (report)
Attributed from
- Cutting Edge (campaign)
- Ivanti VPN Zero-Day Exploit Activity (CVE-2025-0282) (campaign)