UTA0178

THREAT ACTOR PROFILE

UTA0178

UTA0178

UTA0178

UNC5221

UTA0178 is a China-nexus espionage cluster best known for rapidly weaponizing edge-device zero-days, especially in Ivanti Connect Secure and Ivanti EPMM. It deploys the stealthy BRICKSTORM backdoor for long dwell times, often more than a year, against legal, technology, SaaS and government targets, and it has been tied to activity around the F5 BIG-IP source-code breach.

China

Technology / Legal / Government

First seen

2023

Latest IOC

-

IP indicators

Hosts

SHA256 hashes

Posts

NAMES AND ALIASES

UTA0178, UNC5221 and QuietCrabs

UTA0178 is tracked under several research names across vendors. It maps to one entry among the China-nexus espionage groups we profile, and its edge-device exploitation overlaps with clusters like UNC3886.

-

-

-

GROUP PROFILE

Edge-device zero-days and year-long dwell

UTA0178 is a China-nexus espionage actor focused on perimeter appliances. It moves fast on newly disclosed or zero-day flaws in internet-facing devices, establishes quiet persistence, and stays hidden for extended periods to collect intelligence.

Our record places its origin as China and ties it to espionage across technology, legal, SaaS and government sectors. Mandiant and GTIG have responded to BRICKSTORM intrusions with average dwell times near 13 months.

The group's signature is BRICKSTORM, a Go-based backdoor with Linux and Windows variants, paired with KrustyLoader and WIREFIRE on compromised Ivanti appliances.

Facts:

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Victims reported in our records and posts:

-

-

-

-

-

ATTACK LIFECYCLE

Appliance exploitation into BRICKSTORM

The stages below come from UTA0178 and UNC5221 activity in posts we track on our IOC Hunter feed.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

MALWARE AND TOOLING

CVES EXPLOITED

Ivanti, SharePoint and F5 appliance flaws

CVE-2026-21509

A Microsoft Office security bypass used to open the fileless chain in Operation Neusploit, and again in the PixyNetLoader intrusion chain. Both campaigns paired the exploit with spear-phishing from compromised accounts rather than mass exploitation.

CVE-2026-21509

A Microsoft Office security bypass used to open the fileless chain in Operation Neusploit, and again in the PixyNetLoader intrusion chain. Both campaigns paired the exploit with spear-phishing from compromised accounts rather than mass exploitation.

CVE-2026-21509

A Microsoft Office security bypass used to open the fileless chain in Operation Neusploit, and again in the PixyNetLoader intrusion chain. Both campaigns paired the exploit with spear-phishing from compromised accounts rather than mass exploitation.

UTA0178

IOCS FROM HUNT.IO PLATFORM

Latest IOCs

We currently track - IP indicators, - hosts, and - SHA256 hashes for Akira across - intelligence posts, with the most recent indicator dated -. The sample below is limited to indicators from the latest posts. It is not the full set.

UTA0178

Hosting Company

IPs

Date

Hosting Company

IPs

Date

144.126.202.227

LameHug exfil

06-17

Showing a sample of recent indicators

Get the complete

UTA0178

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

UTA0178

IOC set, full IP, host and hash history.

NOTABLE CAMPAIGNS

BRICKSTORM and the Ivanti EPMM wave

Recent reporting tracks UNC5221's backdoor and appliance exploitation.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

Showing a sample of recent indicators

Get the complete

UTA0178

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

UTA0178

IOC set, full IP, host and hash history.