Threat Intelligence / Actor / UNC5174

UNC5174

As of 2026-08-05, UNC5174 is a China-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning vulnerability, malware. Also known as UNC6586, Uteus, Earth Lamia, Operation DRAGONCLONE. ATT&CK coverage spans 61 techniques across 15 tactics in 3 of 3 tracked threats. Most-observed techniques: T1190 (Exploit Public-Facing Application), T1016 (System Network Configuration Discovery), T1041 (Exfiltration Over C2 Channel).

Nation: China · 3 tracked threat(s) · Categories: VULNERABILITY, MALWARE

Also known as: UNC6586, Uteus, Earth Lamia, Operation DRAGONCLONE

ATT&CK techniques observed

61 techniques observed across 3 of 3 tracked threats · Stealth (formerly Defense Evasion) (11), Command and Control (10), Execution (6), Resource Development (6), Persistence (5), Credential Access (4)

Tracked threats

Related CVEs

3 CVEs referenced by tracked UNC5174 activity

CVE-2026-4368, CVE-2026-34486, CVE-2026-3055

Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →

Threadlinqs Intelligence