logo

China-Linked Group Breaches Networks via Connectwise, F5 Software Flaws

ID: 3d78f019-1216-566f-9791-b665017838ad

STIX ID: report--3d78f019-1216-566f-9791-b665017838ad

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-03-22

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Mandiant reports that UNC5174 (Uteus), a China-linked initial access broker with possible MSS ties, has been exploiting multiple disclosed vulnerabilities (notably in ConnectWise ScreenConnect and F5 BIG-IP) to compromise organizations across Southeast Asia, the US, the UK, Hong Kong, and NGOs. After gaining access, the actor deploys a C-based downloader (SNOWLIGHT) to fetch an obfuscated Golang backdoor (GOREVERSE), uses tunneling tools including GOHEAVY and the SUPERSHELL framework for reverse SSH and interactive shells, and performs extensive reconnaissance and lateral movement, sometimes even patching exploited appliances to deny access to others.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.