logo

UNC5174 Linux Espionage Campaign (Campaign)

ID: f6680264-1a68-5285-a8be-19066927e041

STIX ID: report--f6680264-1a68-5285-a8be-19066927e041

Feed Name: Wiz Cloud Threat Landscape

Threat Score
90/100

Date Published: 2025-04-16

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

UNC5174, a suspected Chinese state-sponsored threat actor, has conducted a stealthy Linux-focused espionage campaign since at least November 2024 using a custom dropper called SNOWLIGHT to load an in-memory fileless RAT named VShell (executed via memfd_create and fexecve) and deploying Sliver implants as fallback persistence; the actors employ phishing, domain impersonation, and encrypted WebSocket C2 over HTTPS (plus mTLS/WireGuard for Sliver) to evade detection and maintain persistent access across research, government, NGO, and critical infrastructure targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.