UNC5337 is a suspected China-nexus espionage actor targeting Ivanti VPN appliances.
Analyst brief
UNC5337 is a suspected China-nexus espionage actor targeting Ivanti Connect Secure VPN appliances. It exploits CVE-2023-46805 and CVE-2024-21887 to deploy custom malware families such as SPAWNSNAIL, SPAWNMOLE, SPAWNANT, and SPAWNSLOTH. Defenders should immediately patch affected Ivanti devices, monitor logs for suspicious authentication attempts and anomalous network traffic, and investigate TTPs associated with UNC5221.
UNC5337
unknown
UNC5337 is a suspected China-nexus espionage actor that compromised Ivanti Connect Secure VPN appliances as early as Jan. 2024. UNC5337 is suspected to exploit CVE-2023-46805 (authentication bypass) and CVE-2024-21887 (command injection) for infecting Ivanti Connect Secure appliances. UNC5337 leveraged multiple custom malware families including the SPAWNSNAIL passive backdoor, SPAWNMOLE tunneler, SPAWNANT installer, and SPAWNSLOTH log tampering utility. Mandiant suspects with medium confidence that UNC5337 is UNC5221.