UNC5174

THREAT ACTOR PROFILE

UNC5174

UNC5174

UNC5174

UNC5174 is a China-nexus actor, assessed as possibly linked to the Ministry of State Security, that rapidly exploits edge-device and web-application vulnerabilities for access. It deploys the SNOWLIGHT downloader and the VShell RAT, often fileless and in-memory on Linux, and has rotated in a Discord-based Golang backdoor to maintain stealthy, long-term persistence.

China

Government / Technology

First seen

2023

Latest IOC

-

IP indicators

Hosts

SHA256 hashes

Posts

NAMES AND ALIASES

UNC5174, Uteus and the MSS nexus

UNC5174 is tracked mainly under its Mandiant designation and a couple of handles. It maps to one entry among the China-linked espionage clusters we profile, and its edge-focused access tradecraft overlaps with crews like Volt Typhoon.

-

-

-

GROUP PROFILE

N-day edge exploitation into fileless RATs

UNC5174 operates as an access-focused China-nexus actor. It moves quickly on newly disclosed flaws in internet-facing devices and applications, then deploys lightweight, memory-resident tooling to stay hidden.

Our record places its origin as China and ties it to espionage against government, technology and Southeast Asian targets, with reporting also noting US and Canadian victims. The group has used cracked GoCobaltStrike and Metasploit alongside custom tooling.

Its tradecraft centers on SNOWLIGHT, a lightweight ELF downloader that pulls XOR-encoded payloads into memory, and VShell, a cross-platform post-exploitation RAT, with a Discord API backdoor for low-infrastructure persistence.

Facts:

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Victims reported in our records and posts:

-

-

-

-

-

ATTACK LIFECYCLE

Exploitation into SNOWLIGHT and VShell

The stages below come from UNC5174 activity in posts we track on our IOC Hunter feed.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

MALWARE AND TOOLING

CVES EXPLOITED

Edge and web-application flaws for access

CVE-2026-21509

A Microsoft Office security bypass used to open the fileless chain in Operation Neusploit, and again in the PixyNetLoader intrusion chain. Both campaigns paired the exploit with spear-phishing from compromised accounts rather than mass exploitation.

CVE-2026-21509

A Microsoft Office security bypass used to open the fileless chain in Operation Neusploit, and again in the PixyNetLoader intrusion chain. Both campaigns paired the exploit with spear-phishing from compromised accounts rather than mass exploitation.

UNC5174

IOCS FROM HUNT.IO PLATFORM

Latest IOCs

We currently track - IP indicators, - hosts, and - SHA256 hashes for Akira across - intelligence posts, with the most recent indicator dated -. The sample below is limited to indicators from the latest posts. It is not the full set.

UNC5174

Hosting Company

IPs

Date

Hosting Company

IPs

Date

144.126.202.227

LameHug exfil

06-17

Showing a sample of recent indicators

Get the complete

UNC5174

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

UNC5174

IOC set, full IP, host and hash history.

NOTABLE CAMPAIGNS

SNOWLIGHT, VShell and a Discord backdoor

Recent reporting tracks the group's tooling and exploitation.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

Showing a sample of recent indicators

Get the complete

UNC5174

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

UNC5174

IOC set, full IP, host and hash history.