216.73.216.6

UNC5174's evolution in China's ongoing cyber warfare: From SNOWLIGHT to VShell

· Published 16/04/2025 14:51 · Modified 16/04/2025 18:22

Export JSON

Essential information

Published
16/04/2025 14:51
Modified
16/04/2025 18:22
Tags
2025-04-16 china linux sliver snowlight vshell
Related entities
21 observables, 1 intrusion sets (apt), 7 techniques (mitre), 3 malware, 8 others

Description

Chinese state-sponsored threat actor UNC5174 has launched a new campaign using malware and , a Remote Access Trojan. The campaign targets systems, employing domain squatting for phishing and social engineering. acts as a dropper for , which resides in memory as a fileless payload. The attackers use WebSockets for command and control communication, enhancing stealth. UNC5174's motivations include espionage and access brokering. The campaign has been active since November 2024, demonstrating sophisticated techniques such as memory manipulation and defense evasion. This development highlights the threat actor's expanding arsenal and continued support for Chinese government operations.

External references