China-Backed Threat Actor 'UNC5174' Using Open Source Tools in Stealthy Attacks
ID: a371ae11-d96f-5219-a145-5da4681acdcb
STIX ID: report--a371ae11-d96f-5219-a145-5da4681acdcb
Feed Name: Dark Reading
Date Published: 2025-04-15
Date Updated: 2026-05-05
Author: Alexander Culafi, Senior News Writer, Dark Reading
Sysdig research details an active campaign by UNC5174 — a Chinese state-backed actor — deploying Snowlight and Silver malware alongside a fileless, open-source VShell backdoor using WebSocket-based C2 to stealthily target research institutions, government organizations, think tanks, technology firms, NGOs, and critical infrastructure; Sysdig published detection rules and IOCs to help defenders identify the activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
