#unc5174
NVISO has linked VShell to UNC5174, a cyber contractor for the Chinese MSS

www.nviso.eu/blog/nviso-a...
November 6, 2025 at 11:15 AM
Dear UNC5174/China, you have violated THC's Terms & Conditions ("to be used for good purpose and academic research only").

May want to discuss this with your therapist. 🤷‍♂️

www.sentinelone.com/labs/follow-...
June 20, 2025 at 10:17 AM
中国のハッカー UNC5174、検出回避のために Discord の API を悪用して C2 通信チャネルとして悪用
#CybersecurityNews
www.ithome.com.tw/news/172723
中國駭客UNC5174濫用Discord的API,目的是充當C2通訊管道以迴避偵測
資安業者AhnLab針對中國駭客UNC5174活動提出警告,指出駭客濫用Discord的API進行C2通訊,並以開源程式庫DiscordGo打造後門程式,使得櫝關活動難以察覺
www.ithome.com.tw
December 10, 2025 at 2:09 AM
Security researchers at Sysdig discover threat actors repurposing legitimate open source security tools for cyberattacks, with Chinese-sponsored UNC5174 group leveraging Linux-based VShell and other tools to evade detection.
Linux Security Software Turned Against Users
Security researchers at Sysdig discover threat actors repurposing legitimate open source security tools for cyberattacks, with Chinese-sponsored UNC5174 group leveraging Linux-based VShell and other tools to evade detection.
bit.ly
May 18, 2025 at 5:00 PM
UNC5174グループのDiscord Botバックドアマルウェア
#CybersecurityNews
asec.ahnlab.com/ko/91228/
UNC5174 그룹의 Discord Bot 백도어 악성코드 - ASEC
UNC5174 그룹의 Discord Bot 백도어 악성코드 ASEC
asec.ahnlab.com
November 26, 2025 at 3:13 AM
-AWS spots new GRU attacks on critical infrastructure
-APT reports: Ink Dragon, DRBControl, UNC5174, Kimsuky's Android ops
-New exploitation of Gladinet and Fortinet devices
-Backdoor mechanism found in MGT Varnish
-Amazon patches Kindle vulnerability
-Usenix SOUPS 2025 videos
December 17, 2025 at 10:21 AM
Chinese hackers (Houken/UNC5174) exploited three zero-day vulnerabilities (CVE-2024-8963, CVE-2024-9380, CVE-2024-8190) in Ivanti CSA devices, targeting French government and telecoms, deploying web shells, rootkits, and GOREVERSE malware across various sectors.#IvantiCSAZeroDayExploit
July 3, 2025 at 12:01 PM
"The operators behind the UNC5174 and Houken intrusion sets are likely primarily looking for valuable initial accesses to sell to a state-linked actor seeking insightful intelligence."

www.cert.ssi.gouv.fr/cti/CERTFR-2...
July 1, 2025 at 3:59 PM
China-linked UNC5174 group uses SNOWLIGHT malware and VShell RAT to target Linux and macOS systems. SNOWLIGHT acts as a dropper for VShell, enabling remote access. Attacks leverage open-source tools for obfuscation. Initial access vector remains unknown.#SNOWLIGHTVShellThreat
April 16, 2025 at 2:38 AM
This is an Initial Access Broker with a twist. We like to spotlight important and relevant ATT&CK techniques, so this week we’re taking a look at UNC5174’s N-day exploit spree. Here we go:
April 10, 2024 at 3:51 PM
“Google Mandiant security analysts, who believe UNC5174 is a contractor for China's Ministry of State Security (MSS), have observed the threat actor selling access to networks of U.S. defense contractors …”

🚨
#UNC5174
#ChineseMalware
#ChineseHackers
September 30, 2025 at 3:34 PM
-ANSSI describes Houken (UNC5174) as APT IAB supplier
-Kimsuky adopts ClickFix, with a twist
-C4 Attack breaks Chrome's new encryption
-Wind FTP server RCE
-New Chrome zero-day
-IDE bugs show malicious extensions as verified
-leHACK and fwd:cloudsec videos
-LevelBlue buys Trustwave
July 2, 2025 at 7:34 AM
Bösartige Kampagne der APT-Gruppe UNC5174 kombiniert Snowlight und VShell

#Cyberbedrohung #Cybersecurity #Cyberspionage #Linux #Malware #RemoteAccessTrojaner #Snowlight @Sysdig #VShell

netzpalaver.de/2025/...
April 16, 2025 at 2:28 PM
New post: "UNC5174’s SNOWLIGHT Malware: A Deep Dive"

This China-linked APT is using advanced fileless techniques to hack Linux systems. Learn how they operate—and how to stop them. Read more: 👉 tinyurl.com/2p9r972r #CyberThreats #LinuxAdmin
UNC5174’s SNOWLIGHT Malware: A Sophisticated Threat Targeting Linux Systems
Blog com notícias sobre, Linux, Android, Segurança , etc
tinyurl.com
May 18, 2025 at 6:31 PM
China-linked hackers exploit VMware zero-day vulnerability since Oct 2024. Organizations urged to patch immediately. #CyberSecurity #VMware #ZeroDay #UNC5174 Link: thedailytechfeed.com/china-linked...
September 30, 2025 at 3:53 PM
Security researchers at Sysdig discover threat actors repurposing legitimate open source security tools for cyberattacks, with Chinese-sponsored UNC5174 group leveraging Linux-based VShell and other tools to evade detection.
Linux Security Software Turned Against Users
Security researchers at Sysdig discover threat actors repurposing legitimate open source security tools for cyberattacks, with Chinese-sponsored UNC5174 group leveraging Linux-based VShell and other tools to evade detection.
bit.ly
May 4, 2025 at 11:00 AM
Chinese Hackers Target Linux Systems Using SNOWLIGHT Malware and VShell Tool

The China-linked threat actor known as UNC5174 has been attributed to a new campaign that leverages a variant of a known malware dubbed SNOWLIGHT and a new open-source tool called VShell to infect Linux…

#hackernews #news
Chinese Hackers Target Linux Systems Using SNOWLIGHT Malware and VShell Tool
The China-linked threat actor known as UNC5174 has been attributed to a new campaign that leverages a variant of a known malware dubbed SNOWLIGHT and a new open-source tool called VShell to infect Linux systems. "Threat actors are increasingly using open source tools in their arsenals for cost-effectiveness and obfuscation to save money and, in this case, plausibly blend in with the pool of
thehackernews.com
April 16, 2025 at 2:13 PM
"UNC5174 [aka] Uteus was previously documented by Google-owned Mandiant as exploiting security flaws in Connectwise ScreenConnect & F5 BIG-IP software to deliver a C-based ELF downloader named SNOWLIGHT .. designed to fetch a Golang tunneler dubbed GOHEAVY" thehackernews.com/2025/04/chin... #cyber
Chinese Hackers Target Linux Systems Using SNOWLIGHT Malware and VShell Tool
UNC5174 uses SNOWLIGHT and VShell to target Linux and macOS systems, exploiting Ivanti flaws for remote control.
thehackernews.com
April 15, 2025 at 4:27 PM
These intrusions were still ongoing as of last week: "In 2025 alone, Sysdig TRT has detected more than 40 examples of IOCs with VShell that indicate UNC5174 as the threat actor – the latest of which was actually seen today, April 11," Sysdig threat detection engineer Alessandra Rizzo told me.
Chinese spies backdoored US orgs via open source RAT
: Let the espionage and access resale campaigns begin (again)
www.theregister.com
April 15, 2025 at 3:21 PM
China-linked group Houken hit French organizations using zero-days
China-linked group Houken hit French organizations using zero-days
China-linked group UNC5174 hit French govt, telecom, media, finance and transport sectors using Ivanti CSA zero-days, says France’s ANSSI.
securityaffairs.com
July 3, 2025 at 8:25 PM