UNC5325 is a suspected Chinese cyber espionage group targeting Ivanti appliances via CVE-2024-21893.
Analyst brief
UNC5325 is a suspected Chinese cyber espionage group that exploits CVE-2024-21893 to compromise Ivanti Connect Secure appliances. The group targets these appliances by deploying custom malware such as LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK, and modifies device settings to evade detection and maintain persistence. Key TTPs include leveraging open-source code and showing malware code overlaps with UNC3886. Defenders should monitor for indicators related to these malware families and pay attention to unauthorized configuration changes on Ivanti devices.
UNC5325
unknown
UNC5325 is a suspected Chinese cyber espionage operator that exploited CVE-2024-21893 to compromise Ivanti Connect Secure appliances. UNC5325 leveraged code from open-source projects, installed custom malware, and modified the appliance's settings in order to evade detection and attempt to maintain persistence. UNC5325 has been observed deploying LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK. Mandiant identified TTPs and malware code overlaps in LITTLELAMB.WOOLTEA and PITHOOK with malware leveraged by UNC3886. Mandiant assesses with moderate confidence that UNC5325 is associated with UNC3886.