logo

Chinese snoops use F5, ConnectWise bugs to sell access into top US, UK networks

ID: a076e8dc-afc9-5b76-ae5a-0526f23c4ed4

STIX ID: report--a076e8dc-afc9-5b76-ae5a-0526f23c4ed4

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2024-03-22

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Mandiant attributes large-scale exploitation of multiple high-severity vulnerabilities (including CVE-2023-46747 in F5 BIG-IP and CVE-2024-1709 in ConnectWise ScreenConnect) to UNC5174, a China-linked initial-access broker that used a SUPERSHELL C2 and payloads such as SNOWLIGHT, GOHEAVY and GOREVERSE to gain persistent access and sell entry to high-value organizations (US defense, UK government, universities and others); Mandiant assesses with moderate confidence the group may be operating as an MSS contractor and warns defenders to review provided IOCs and hardening guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.