Threat Intelligence / Actor / UNC5174
UNC5174
As of 2026-08-05, UNC5174 is a China-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning vulnerability, malware. Also known as UNC6586, Uteus, Earth Lamia, Operation DRAGONCLONE. ATT&CK coverage spans 61 techniques across 15 tactics in 3 of 3 tracked threats. Most-observed techniques: T1190 (Exploit Public-Facing Application), T1016 (System Network Configuration Discovery), T1041 (Exfiltration Over C2 Channel).
Also known as: UNC6586, Uteus, Earth Lamia, Operation DRAGONCLONE
ATT&CK techniques observed
- T1190 Exploit Public-Facing Application — Initial Access — observed in 3 of 3 tracked threats
- T1016 System Network Configuration Discovery — Discovery — observed in 2 of 3 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltration — observed in 2 of 3 tracked threats
- T1046 Network Service Discovery — Discovery — observed in 2 of 3 tracked threats
- T1071 Application Layer Protocol — Command and Control — observed in 2 of 3 tracked threats
- T1572 Protocol Tunneling — Command and Control — observed in 2 of 3 tracked threats
- T1573 Encrypted Channel — Command and Control — observed in 2 of 3 tracked threats
- T1588 Obtain Capabilities — Resource Development — observed in 2 of 3 tracked threats
- T1595 Active Scanning — Reconnaissance — observed in 2 of 3 tracked threats
- T1005 Data from Local System — Collection — observed in 1 of 3 tracked threats
- T1021 Remote Services — Lateral Movement — observed in 1 of 3 tracked threats
- T1021.001 Remote Desktop Protocol — Lateral Movement — observed in 1 of 3 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 1 of 3 tracked threats
- T1027.013 Encrypted/Encoded File — Stealth (formerly Defense Evasion) — observed in 1 of 3 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion) — observed in 1 of 3 tracked threats
Tracked threats
- CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass Actively Exploited in SnowLight and AI-Assisted Campaigns — HIGH
- CitrixBleed 3 — CVE-2026-3055 & CVE-2026-4368 NetScaler ADC/Gateway Memory Overread and Session Hijack — CRITICAL
- Vshell C2 Framework — Chinese-Language Cobalt Strike Alternative in APT Campaigns (UNC5174/SNOWLIGHT, Operation DRAGONCLONE) — HIGH
Related CVEs
CVE-2026-4368, CVE-2026-34486, CVE-2026-3055
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →