UTA0178

Aliases: UNC5221, Red Dev 61

First seen
2021-05-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Last IoC activity
2026-06-08 12:56:46
Profile updated
2026-07-07 11:48:41

Targeted industries: government-and-public-sector technology-and-telecommunications energy-and-utilities

Targeted regions: country_code:us country_code:uk country_code:au

Context

While Volexity largely observed the attacker essentially living off the land, they still deployed a handful of malware files and tools during the course of the incident which primarily consisted of webshells, proxy utilities, and file modifications to allow credential harvesting. Once UTA0178 had access into the network via the ICS VPN appliance, their general approach was to pivot from system to system using compromised credentials. They would then further compromise credentials of users on any new system that was breached, and use these credentials to log into additional systems via RDP. Volexity observed the attacker obtaining credentials in a variety of ways.

Related threat objects

Reports & references

  • bsi.bund.de — Aktive Apt Gruppen Node (report)
  • volexity.com — Active Exploitation Of Two Zero Day Vulnerabilities In Ivanti Connect Secure Vpn (report)
  • rewterz.com — Rewterz Threat Advisory Ivanti Vpn Zero Days Weaponized By Unc5221 Threat Actors To Deploy Multiple Malware Families Active Iocs (report)
  • Mandiant — Suspected Apt Targets Ivanti Zero Day (report)
  • quointelligence.eu — Unc5221 Unreported And Undetected Wirefire Web Shell Variant (report)
  • volexity.com — Ivanti Connect Secure Vpn Exploitation New Observations (report)
  • Mandiant — Investigating Ivanti Zero Day Exploitation (report)
  • cloud.google.com — Ivanti Post Exploitation Lateral Movement (report)

Attributed from

  • Cutting Edge (campaign)
  • Ivanti VPN Zero-Day Exploit Activity (CVE-2025-0282) (campaign)

External references