#Unc5221
New Ivanti zero-day: forums.ivanti.com/s/article/Ap...

Mandiant links it to a known Chinese APT (UNC5221): cloud.google.com/blog/topics/...
April 3, 2025 at 4:57 PM
Hot off the press is a new blog detailing our observations from in the wild exploitation of CVE-2025-22457 by UNC5221 including two newly observed malware families tracked as BRUSHFIRE and TRAILBLAZE.

cloud.google.com/blog/topics/...
Suspected China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457) | Google Cloud Blog
cloud.google.com
April 3, 2025 at 4:26 PM
China-linked APT UNC5221 started exploiting Ivanti EPMM flaws shortly after their disclosure
China-linked APT UNC5221 started exploiting Ivanti EPMM flaws shortly after their disclosure
China-linked APT exploit Ivanti EPMM flaws to target critical sectors across Europe, North America, and Asia-Pacific, according to EclecticIQ.
securityaffairs.com
May 26, 2025 at 12:18 PM
Chinese mashers spent 18 months inside Microsoft 365 before anyone noticed #ClownSecurity #Potatosecurity #Unc5221
June 7, 2026 at 1:15 PM
-Hunters international prepares to shut down and rebrand
-Babuk2 gang linked to data broker Bjorka
-Stripe API abused for skimming
-Abuse of SVG redirects becomes mainstream
-UNC5221 deploys new Ivanti zero-day
-DrayTek reboot loops linked to pre-2020 bugs
-Five Eyes warns about fast flux networks
April 4, 2025 at 8:59 AM
Chinese APT deploys new malware to keep access to hacked networks
Chinese APT deploys new malware to keep access to hacked networks
A Chinese espionage group tracked as UNC5221 has been accessing Microsoft 365 environments using the Brickstorm backdoor and previously undocumented malware named Plenet and AgentPSD.
www.bleepingcomputer.com
June 5, 2026 at 6:41 PM
🇨🇳 UNC5221 China-Nexus Threat Actor Actively Exploiting Ivanti EPMM (CVE-2025-4428).Targets critical networks like US airports and Telecommunications companies in EU. Exfiltrating sensitive data from managed mobile devices. #cyber

Here is the full report:

blog.eclecticiq.com/china-nexus-...
May 22, 2025 at 11:34 AM
Chinese threat actor UNC5221 has significantly upgraded their BRICKSTORM malware with triple-layer encryption that renders most security monitoring ineffective, according to NVISO Security.

#SecurityLand #CyberWatch #CyberSecurity #ThreatIntelligence #APT #Brickstorm #Malware
BRICKSTORM Malware Evolves: Deploying Triple-Layer Encryption to Bypass Enterprise Security | Security Land
Chinese-linked UNC5221 expands BRICKSTORM attack surface from Linux to Windows using three-layer encryption and tunneling to bypass security.
www.security.land
April 16, 2025 at 6:25 PM
Chinese hackers (Silk Typhoon/UNC5221) breached 400+ US Treasury computers, accessing 3,000+ unclassified files on sanctions, investment, and investigations. No classified data was compromised.#SilkTyphoonTreasuryBreach
January 16, 2025 at 5:08 AM
The suspect is associated with Halfnium aka Silk Typhoon aka UNC5221, a pretty serious outfit that regularly uses zerodays and targets technology providers in supply chain attacks. He was allegedly specifically involved in cyberespionage targeting COVID-19 research. 2/x
July 8, 2025 at 7:54 PM
UNC5221 stuffing stockings at the edge? Updated odds: 32% they pop a fresh zero‑day before 12/31. Attribution lags, year‑end windows don’t. 🔥🛡️

Peek the forecast—then subscribe for the follow-through. -> blog.alphahunt.io/will-unc5221...

#AlphaHunt #CyberSecurity #ZeroDay #UNC5221
Will UNC5221 pop a fresh zero-day before Dec 31? Updated!
UNC5221 is an edge-focused PRC espionage actor repeatedly tied to zero-days (Ivanti 2023–2025; prior NetScaler). Edge products remained a major zero-day target in 2024. But public attributions…
blog.alphahunt.io
November 17, 2025 at 2:03 PM
UNC5221 (China-nexus) exploited Ivanti EPMM flaws (CVE-2025-4427/4428) using KrustyLoader and Sliver, targeting global enterprises (healthcare, telecom, aviation, government). Database access and reverse shells were achieved.#UNC5221KrustySliverAttack
May 22, 2025 at 2:01 PM
China-linked hackers are using a backdoor called BRICKSTORM to steal intellectual property from law firms, SaaS, and tech companies, targeting executive inboxes. Mandiant attributes it to UNC5221.
#BRICKSTORM #China #Mandiant #UNC5221 #CyberSecurity #Infosec #IPTheft therecord.media/china-linked...
China-linked hackers use ‘BRICKSTORM’ backdoor to steal IP
Researchers said the BRICKSTORM campaign stood out because of its “sophistication, evasion of advanced enterprise security defenses and focus on high-value targets.”
therecord.media
September 25, 2025 at 5:58 PM
UNC5221’s holiday plan: edge 0-days. 32% by Dec 31—watch GTI/Mandiant + CISA KEV for a buzzer-beater. 🎄🔐

Beat the press release—subscribe for the final call.

blog.alphahunt.io/will-unc5221...

#AlphaHunt #CyberSecurity #ZeroDay
Will UNC5221 pop a fresh zero-day before Dec 31? Updated!
UNC5221 is an edge-focused PRC espionage actor repeatedly tied to zero-days (Ivanti 2023–2025; prior NetScaler). Edge products remained a major zero-day target in 2024. But public attributions…
blog.alphahunt.io
November 23, 2025 at 4:28 PM
Urgent: Chinese hackers (UNC5221) exploit Ivanti Connect Secure vulnerability (CVE-2025-22457), deploying Spawn/Brushfire malware. Patch (Feb 11th) available, but not for EOL devices. CISA urges immediate action.#UNC5221SpawnBrushfireAlert
April 5, 2025 at 2:10 PM
China-backed espionage group hits Ivanti customers again. UNC5221 has a knack for exploiting defects in Ivanti products. The group has exploited at least four vulnerabilities in the vendor’s products since 2023, according to Mandiant. via @mattkapko.com cyberscoop.com/china-espion...
China-backed espionage group hits Ivanti customers again
UNC5221 has a knack for exploiting defects in Ivanti products. The group has exploited at least four vulnerabilities in the vendor’s products since 2023, according to Mandiant.
cyberscoop.com
April 3, 2025 at 11:32 PM
Chinese UNC5221 Exploitation of Ivanti Connect Secure
Chinese UNC5221 Exploitation of Ivanti Connect Secure
UNC5221 is an advanced and highly sophisticated espionage group believed to have ties to China. This group has demonstrated significant expertise in targeting edge devices and exploiting critical v…
thecyberthrone.in
April 4, 2025 at 9:33 AM
A Chinese APT (UNC5221) is behind recent attacks exploiting an Ivanti zero-day (CVE-2025-4427)

This is a known Chinese APT group that seems to be specialized in Ivanti and other Western enterprise products... they have a long list of past zero-days in their name

blog.eclecticiq.com/china-nexus-...
China-Nexus Threat Actor Actively Exploiting Ivanti Endpoint Manager Mobile (CVE-2025-4428) Vulnerability
On Thursday, May 15, 2025, Ivanti disclosed two critical vulnerabilities - CVE-2025-4427 and CVE-2025-4428 - affecting Ivanti Endpoint Manager Mobile (EPMM) version 12.5.0.0 and earlier.
blog.eclecticiq.com
May 22, 2025 at 11:32 AM
中国のAPTが、ハッキングしたネットワークへのアクセスを維持するために新たなマルウェアを展開

UNC5221として追跡されている中国のスパイグループが、Brickstormバックドアと、これまで記録されていなかったPlenetおよびAgentPSDというマルウェアを使用して、Microsoft 365環境にアクセスしていたことが明らかになった。

この事件の調査により、攻撃者は検出される少なくとも18ヶ月前には被害者のネットワークにアクセスしており、被害者組織のマネージドサービスプロバイダー(MSP)も侵害していたことが明らかになった。

UNC5221はVerdantBambooとし...
Chinese APT deploys new malware to keep access to hacked networks
A Chinese espionage group tracked as UNC5221 has been accessing Microsoft 365 environments using the Brickstorm backdoor and previously undocumented malware named Plenet and AgentPSD.
www.bleepingcomputer.com
July 1, 2026 at 8:06 PM
UNC5221 uses BRICKSTORM backdoor to target US legal & tech sectors, stealing data & IP. Mandiant & Google report sustained attacks since at least Nov 2022. Initial access via Ivanti Connect Secure exploits. #Cybersecurity #News
UNC5221 Uses BRICKSTORM Backdoor to Infiltrate U.S. Legal and Technology Sectors
UNC5221 uses BRICKSTORM backdoor to target US legal & tech sectors, stealing data & IP. Mandiant & ...
thehackernews.com
September 24, 2025 at 10:04 PM
Japan's CERT looks at DslogdRAT, a web shell deployed on hacked Ivanti Connect Secure devices—typically via CVE-2025-0282

These initial attacks were linked to Chinese APT UNC5221, but it's unclear if DslogdRAT is their malware, or may belong to a different group

blogs.jpcert.or.jp/en/2025/04/d...
DslogdRAT Malware Installed in Ivanti Connect Secure - JPCERT/CC Eyes
In a previous article of JPCERT/CC Eyes, we reported on SPAWNCHIMERA malware, which infects the target after exploiting the vulnerability in Ivanti Connect Secure. However, this is not the only malwar...
blogs.jpcert.or.jp
April 24, 2025 at 10:49 AM
New Year, same edge appliances. UNC5221’s camping in vCenter/ESXi + F5 “source-code drama”… and we still price a fresh 0-day at 11%. Your patch queue isn’t a talisman. 🥂🔧

Read the forecast (then subscribe): blog.alphahunt.io/will-unc5221...

#AlphaHunt #CyberSecurity #ZeroDay #VMware
Will UNC5221 pop a fresh zero-day before Dec 31? Final Forecast!
BRICKSTORM intel just landed: PRC actors camping in vCenter/ESXi + Windows. 🧱🕵️‍♂️ F5 source-code drama raises the long-run 0-day odds, but the calendar + attribution lag are savage. Our final…
blog.alphahunt.io
January 9, 2026 at 10:25 PM
Edge boxes = no EDR. UNC5221 feasts. 55% odds of a new edge 0‑day by Dec 31.

🔥 Subscribe for sharper forecasts—before the boom.

blog.alphahunt.io/by-dec-31-20...

#AlphaHunt #CyberSecurity #ZeroDay #APT
By Dec 31, 2025, will UNC5221 be publicly linked to exploiting at least one new zero-day?
Question: By Dec 31, 2025, will UNC5221 be publicly linked to exploiting at least one new zero-day in a non-Ivanti edge platform (e.g., VMware vCenter/ESXi, Citrix NetScaler, F5, Palo Alto, Fortinet)?
blog.alphahunt.io
November 7, 2025 at 10:25 PM