UNC5221 — APT Profile
UNC5221 exploited Ivanti Connect Secure VPN zero-days to compromise global government and critical infrastructure networks.Also tracked as
UTA0178, UNC5337
Tools & malware
- BRUSHFIRE Backdoor
- BUSHWALK Webshell
- CHAINLINE Webshell
- DRYHOOK Stealer
- FRAMESTING Webshell
- GLASSTOKEN Webshell
- LIGHTWIRE Webshell
- PHASEJAM Loader
- SPAWNANT Loader
- SPAWNMOLE Tool
- SPAWNSLOTH Tool
- SPAWNSNAIL Backdoor
- SPAWNSNARE Tool
- THINSPOOL Loader
- TRAILBLAZE Loader
- WARPWIRE Stealer
- WIREFIRE Webshell
- ZIPLINE Backdoor
Vendor research
- Active Exploitation of Two Zero-Day Vulnerabilities in Ivanti Connect Secure VPN Volexity
- Cutting Edge: Suspected APT Targets Ivanti Connect Secure VPN in New Zero-Day Exploitation Mandiant (Google Cloud)
- Cutting Edge, Part 2: Investigating Ivanti Connect Secure VPN Zero-Day Exploitation Mandiant (Google Cloud)
- Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation Mandiant (Google Cloud)
- Suspected China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457) Mandiant (Google Cloud)
- UNC5221: Unreported and Undetected WIREFIRE Web Shell Variant QuoIntelligence