Home/Threat Actor/UNC5325 (Ivanti Connect Secure 2024 Operator)
Threat Actor

UNC5325 (Ivanti Connect Secure 2024 Operator)

unc5325 · china_nexus_suspected_mandiant_unc5325_ivanti_2024_zero_day_specialist · active since 2024-01

UNC5325 is Mandiant's tracked uncategorized threat cluster designation for the suspected China-nexus actor behind January-February 2024 Ivanti Connect Secure (formerly Pulse Secure) zero-day exploitation chain involving CVE-2024-21887 command injection + CVE-2023-46805 authentication bypass + CVE-2024-22024 XML External Entity (XXE) vulnerabilities with LITTLELAMB.WOOLTEA factory- reset-surviving persistent backdoor + PITSTOP + PITDOG + PITJET + PITHOOK custom malware family + Ivanti Integrity Checker Tool (ICT) bypass capability + suspected UNC5221 operational overlap.

suspected China-nexus attribution per Mandiant Cutting Edge blog series + Ivanti canonical vulnerability disclosures + CISA Emergency Directive 24-01 issued January 31 2024 directing federal civilian executive branch agencies to disconnect Ivanti Connect Secure + Policy Secure appliances + Mandiant Cutting Edge Part 3 Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts + Mandiant Cutting Edge Part 4 Ivanti Connect Secure VPN Post-Exploitation Lateral Movement; honest attribution caveat UNC5325 is Mandiant uncategorized cluster designation with suspected operational overlap with UNC5221 (Mandiant tracking, curated as silk_typhoon umbrella cluster in corpus, distinct UNC5325 designation reflects Mandiant clustering discipline) + suspected China-nexus attribution per Mandiant is less definitive than UNC4841/UNC3886 high- confidence China-nexus attribution + UNC5221 (silk_typhoon) was primary actor in initial Ivanti Connect Secure 2024 zero-day exploitation campaign while UNC5325 represents Mandiant's distinct tracking of follow-on or related operations.

standalone cluster paralleling apt5_unc2630 + unc3886 + unc4841 in v0.1.175 Mandiant UNC/APT Chinese-state-sponsored zero- day specialist cluster cell.

operational target profile signature government + defense industrial base + high-technology + telecommunications multi-sector targeting per Mandiant + signature globally distributed operational footprint + signature Ivanti Connect Secure + Policy Secure appliance operators target population reflecting enterprise VPN/remote-access infrastructure espionage targeting consistent with broader China-nexus state-sponsored zero-day specialist methodology.

operational attack architecture: (1) cluster-defining Ivanti Connect Secure 2024 zero-day exploitation chain canonical case with January 10 2024 Ivanti initial disclosure of CVE-2023-46805 + CVE-2024-21887 + January 31 2024 CISA Emergency Directive 24-01 + February 8 2024 CVE-2024-22024 XXE chain extension establishing 3-CVE exploitation chain signature; (2) cluster-defining CVE-2024-21887 command injection RCE binding with critical CVSS 9.1 severity remote command injection in Ivanti Connect Secure + Policy Secure web components; (3) cluster-defining CVE-2023-46805 authentication bypass binding with CVSS 8.2 severity authentication bypass enabling unauthenticated access to restricted resources.

(4) cluster- defining CVE-2024-22024 XML External Entity (XXE) binding with CVSS 8.3 severity XXE vulnerability in Ivanti Connect Secure web components extending the exploitation chain; (5) cluster-defining LITTLELAMB.WOOLTEA persistent backdoor signature designed to survive Ivanti factory reset operations through sophisticated firmware/storage persistence mechanisms, distinguishing UNC5325 tradecraft from conventional appliance backdoors.

(6) cluster-defining PITSTOP + PITDOG + PITJET + PITHOOK custom malware family signature establishing post-compromise persistence + lateral movement capability + command-and-control infrastructure for sustained operational access; (7) cluster-defining Ivanti ICT Integrity Checker Tool bypass capability signature with sophisticated detection-evasion against Ivanti's compromised-appliance detection mechanism through LITTLELAMB.WOOLTEA persistence mechanisms.

(8) cluster-defining suspected UNC5221 operational overlap signature with Mandiant distinct- tracking methodology preserving UNC5325 as follow-on/related-operations cluster separate from UNC5221 primary initial-exploitation tracking.

(9) signature post-perimeter LOTL tradecraft + organic-infrastructure usage paralleling KOSTOVITE Dragos-tracked operational methodology consistent with broader Chinese- state-sponsored APT operational patterns; (10) signature CISA Emergency Directive 24-01 industry-disrupting response signature with federal civilian executive branch agencies directed to disconnect all Ivanti Connect Secure + Policy Secure appliances pending vendor remediation; cluster fills the Mandiant-UNC5325-suspected- China-nexus-attribution + Ivanti-Connect-Secure- 2024-zero-day-exploitation-chain + CVE-2024- 21887-CVE-2023-46805-CVE-2024-22024-canonical- CVE-chain + LITTLELAMB.WOOLTEA-PITSTOP-PITDOG- PITJET-PITHOOK-custom-malware-family + Ivanti- ICT-bypass-capability + suspected-UNC5221- operational-overlap + January-February-2024- canonical-disclosure-timing position in v0.1.175 Mandiant UNC/APT Chinese-state-sponsored zero- day specialist cluster cell.

canonical illustration of Mandiant suspected-China-nexus attribution methodology + Ivanti Connect Secure 2024 zero- day chain industry-defining case + LITTLELAMB.WOOLTEA factory-reset-surviving persistent backdoor + PITSTOP/PITDOG/PITJET/PITHOOK custom malware family + Ivanti ICT bypass tradecraft + suspected UNC5221 operational overlap distinct-tracking methodology + CISA Emergency Directive 24-01 industry-disrupting response cited in essentially all subsequent China-nexus Ivanti-zero-day industry analyses through 2024-2026 period.

china_nexus_suspected_mandiant_unc5325_ivanti_2024_zero_day_specialist confidence: high 14 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited3

Profile

UNC5325 is Mandiant's tracked uncategorized threat cluster designation for the suspected China-nexus actor behind January-February 2024 Ivanti Connect Secure (formerly Pulse Secure) zero-day exploitation chain involving CVE-2024-21887 + CVE-2023-46805 + CVE-2024-22024 vulnerabilities with LITTLELAMB.WOOLTEA factory-reset-surviving persistent backdoor + PITSTOP + PITDOG + PITJET + PITHOOK custom malware family + Ivanti ICT bypass capability + suspected UNC5221 operational overlap. Suspected China-nexus attribution per Mandiant Cutting Edge blog series + Ivanti canonical vulnerability disclosures + CISA Emergency Directive 24-01. Honest attribution caveat: UNC5325 is Mandiant uncategorized cluster with suspected operational overlap with UNC5221 (Mandiant tracking, curated as silk_typhoon umbrella).

Suspected China-nexus attribution per Mandiant is less definitive than UNC4841/UNC3886 high-confidence China-nexus attribution. Standalone cluster paralleling apt5_unc2630 + unc3886 + unc4841 in v0.1.175 Mandiant UNC/APT Chinese-state-sponsored zero-day specialist cluster cell.

Operational target profile
  • Government signature.
  • Defense industrial base signature.
  • High-technology signature.
  • Telecommunications signature.
  • Globally distributed Operational attack architecture: (1) Ivanti Connect Secure 2024 zero-day chain (cluster-defining) (2) CVE-2024-21887 + CVE-2023-46805 + CVE-2024- 22024 3-CVE chain (cluster-defining) (3) LITTLELAMB.WOOLTEA factory-reset-surviving persistent backdoor (cluster-defining) (4) PITSTOP + PITDOG + PITJET + PITHOOK custom malware family (cluster-defining) (5) Ivanti ICT bypass capability (cluster- defining) (6) Suspected UNC5221 operational overlap (cluster-defining) (7) Post-perimeter LOTL + organic infrastructure (signature) The cluster fills the Mandiant-UNC5325-suspected- China-nexus-attribution + Ivanti-Connect-Secure- 2024-zero-day-exploitation-chain + CVE-2024- 21887-CVE-2023-46805-CVE-2024-22024-canonical- CVE-chain + LITTLELAMB.WOOLTEA-PITSTOP-PITDOG- PITJET-PITHOOK-custom-malware-family + Ivanti- ICT-bypass-capability + suspected-UNC5221- operational-overlap + January-February-2024- canonical-disclosure-timing position in v0.1.175 Mandiant UNC/APT Chinese-state-sponsored zero- day specialist cluster cell.

Aliases

14
unc5325unc_5325unc5325 activity clustermandiant unc5325 trackingunc5325 ivanti connect secure 2024 zero-day exploitationunc5325 cve-2024-21887 cve-2023-46805 cve-2024-22024 exploitation chainunc5325 littlelamb.wooltea backdoor signatureunc5325 pitstop pitdog pitjet pithook custom malware familyunc5325 suspected china-nexus mandiant attributionunc5325 unc5221 suspected overlap trackingunc5325 ivanti connect secure pulse secure successor 2024 campaignunc5325 january february 2024 zero-day campaignunc5325 living off the land binary tradecraft signatureunc5325 perimeter device specialist mandiant

Notable Campaigns

10
2024-2026Continued Industry Reference Status (2024-2026)
2024UNC5325 January 10 2024 Ivanti Connect Secure Initial Zero-Day Disclosure
2024UNC5325 CISA Emergency Directive 24-01 Disconnect Affected Appliances Signature
2024UNC5325 February 8 2024 CVE-2024-22024 XXE Chain Extension Signature
2024UNC5325 Mandiant Canonical UNC5325 Suspected China-Nexus Attribution Signature
2024UNC5325 LITTLELAMB.WOOLTEA Factory-Reset-Surviving Persistent Backdoor Signature
2024UNC5325 PITSTOP + PITDOG + PITJET + PITHOOK Custom Malware Family Signature
2024UNC5325 Ivanti ICT Integrity Checker Tool Bypass Capability Signature
2024UNC5325 Suspected UNC5221 Operational Overlap Signature
2024UNC5325 Post-Perimeter LOTL + Organic Infrastructure Signature

Attribution & Reporting

Attributed by
Mandiant (canonical UNC5325 suspected China-nexus attribution + Ivanti Connect Secure 2024 zero-day disclosure)Ivanti (canonical CVE-2023-46805 + CVE-2024-21887 + CVE-2024-22024 disclosure)CISA (canonical Emergency Directive 24-01)Mandiant blog "Cutting Edge - Part 3 - Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts" (canonical UNC5325 attribution)Mandiant blog "Cutting Edge - Part 4 - Ivanti Connect Secure VPN Post-Exploitation Lateral Movement" (canonical follow-on)
Key reporting
reportMandiant (Feb 2024): canonical UNC5325 Ivanti Connect Secure 2024 zero-day attribution
reportMandiant Cutting Edge Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts
reportMandiant Cutting Edge Part 4: Ivanti Connect Secure VPN Post-Exploitation Lateral Movement
reportIvanti: canonical CVE-2023-46805 + CVE-2024-21887 + CVE-2024-22024 disclosures
reportCISA: canonical Emergency Directive 24-01

Operational

State sponsor

UNC5325 is Mandiant's tracked uncategorized threat cluster designation for the suspected China-nexus actor behind January-February 2024 Ivanti Connect Secure (formerly Pulse Secure) zero-day exploitation chain involving CVE-2024-21887 command injection + CVE-2023-46805 authentication bypass + CVE-2024-22024 XML External Entity (XXE) vulnerabilities. Per Mandiant: UNC5325 is assessed as a suspected China-nexus espionage actor. Honest attribution caveat: UNC5325 is Mandiant's uncategorized cluster designation with suspected operational overlap with UNC5221 (Mandiant tracking already curated in corpus as silk_typhoon umbrella cluster but distinct UNC5325 designation reflects Mandiant clustering discipline). Suspected China- nexus attribution per Mandiant is less definitive than UNC4841/UNC3886 high-confidence China-nexus attribution. UNC5221 (curated as silk_typhoon) was the primary actor behind initial Ivanti Connect Secure 2024 zero-day exploitation; UNC5325 represents Mandiant's distinct tracking of follow-on or related operations. Attribution chain: (1) Mandiant canonical UNC5325 designation + February 2024 Ivanti Connect Secure zero-day disclosure: Mandiant published UNC5325 disclosure attributing the Ivanti Connect Secure 2024 zero- day exploitation chain involving CVE-2024-21887 + CVE-2023-46805 + CVE-2024-22024 to suspected China-nexus espionage actor. (2) Ivanti Connect Secure 2024 zero-day exploitation chain canonical: January 10 2024: Ivanti disclosed CVE-2023-46805 (authentication bypass) + CVE-2024-21887 (command injection) as zero-day vulnerabilities. January 31 2024: CISA issued Emergency Directive 24-01 directing federal agencies to disconnect Ivanti Connect Secure + Policy Secure appliances. February 8 2024: Ivanti disclosed CVE-2024-22024 XXE vulnerability extending the exploitation chain. (3) LITTLELAMB.WOOLTEA backdoor + PITSTOP + PITDOG + PITJET + PITHOOK custom malware family signature: per Mandiant: UNC5325 deployed LITTLELAMB.WOOLTEA persistent backdoor designed to survive Ivanti factory reset operations + PITSTOP + PITDOG + PITJET + PITHOOK custom malware components establishing post-compromise persistence + lateral movement capability. (4) Ivanti Integrity Checker Tool (ICT) bypass capability signature: per Mandiant: UNC5325 demonstrated sophisticated capability to bypass Ivanti's Integrity Checker Tool (ICT) which Ivanti deployed as detection mechanism for compromised appliances, evading detection through LITTLELAMB.WOOLTEA persistence mechanisms. (5) Suspected UNC5221 operational overlap signature: per Mandiant: UNC5325 has suspected operational overlap with UNC5221 (Mandiant tracking, curated as silk_typhoon umbrella in corpus) which was primary actor in initial Ivanti Connect Secure 2024 zero-day exploitation campaign.

UNC5325 represents Mandiant's distinct tracking of follow-on or related operations.

Operational target profile
  • Ivanti Connect Secure + Policy Secure appliance operators signature target population.
  • Government signature per Mandiant.
  • Defense industrial base per Mandiant.
  • High-technology per Mandiant.
  • Telecommunications per Mandiant.
  • Globally distributed per Mandiant The cluster fills the Mandiant-UNC5325-suspected- China-nexus-attribution + Ivanti-Connect-Secure- 2024-zero-day-exploitation-chain + CVE-2024- 21887-CVE-2023-46805-CVE-2024-22024-canonical- CVE-chain + LITTLELAMB.WOOLTEA-PITSTOP-PITDOG- PITJET-PITHOOK-custom-malware-family + Ivanti- ICT-bypass-capability + suspected-UNC5221- operational-overlap + January-February-2024- canonical-disclosure-timing position in v0.1.175 Mandiant UNC/APT Chinese-state-sponsored zero- day specialist cluster cell.
Motivations
china_nexus_suspected_mandiant_unc5325_designation, ivanti_connect_secure_2024_zero_day_exploitation_chain_signature, littlelamb_wooltea_persistent_backdoor_factory_reset_survival, pitstop_pitdog_pitjet_pithook_custom_malware_family_signature, ivanti_ict_integrity_checker_tool_bypass_capability_signature, suspected_unc5221_operational_overlap_distinct_mandiant_tracking
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)56/60 · 93%
Analytics (MITRE CAR)30/60 · 50%
Runtime / container (Falco)9/60 · 15%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)19/60 · 31%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
SUSPECTED CHINA-NEXUS MANDIANT ATTRIBUTION LESS-DEFINITIVE-THAN-HIGH-CONFIDENCESUSPECTED UNC5221 OPERATIONAL OVERLAP MANDIANT DISTINCT TRACKING

CVEs Exploited

3
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin