# UNC5174

> As of 2026-08-05, UNC5174 is a China-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning vulnerability, malware. Also known as UNC6586, Uteus, Earth Lamia, Operation DRAGONCLONE. ATT&CK coverage spans 61 techniques across 15 tactics in 3 of 3 tracked threats. Most-observed techniques: T1190 (Exploit Public-Facing Application), T1016 (System Network Configuration Discovery), T1041 (Exfiltration Over C2 Channel).

- **Nation:** China
- **Tracked threats:** 3
- **Categories:** VULNERABILITY, MALWARE
- **Also known as:** UNC6586, Uteus, Earth Lamia, Operation DRAGONCLONE
- **As of:** 2026-08-05

## ATT&CK techniques observed

61 techniques observed across 3 of 3 tracked threats. Tactics: Stealth (formerly Defense Evasion) (11), Command and Control (10), Execution (6), Resource Development (6), Persistence (5), Credential Access (4).

- [T1190](https://attack.mitre.org/techniques/T1190/) Exploit Public-Facing Application — Initial Access — observed in 3 of 3 tracked threats
- [T1016](https://attack.mitre.org/techniques/T1016/) System Network Configuration Discovery — Discovery — observed in 2 of 3 tracked threats
- [T1041](https://attack.mitre.org/techniques/T1041/) Exfiltration Over C2 Channel — Exfiltration — observed in 2 of 3 tracked threats
- [T1046](https://attack.mitre.org/techniques/T1046/) Network Service Discovery — Discovery — observed in 2 of 3 tracked threats
- [T1071](https://attack.mitre.org/techniques/T1071/) Application Layer Protocol — Command and Control — observed in 2 of 3 tracked threats
- [T1572](https://attack.mitre.org/techniques/T1572/) Protocol Tunneling — Command and Control — observed in 2 of 3 tracked threats
- [T1573](https://attack.mitre.org/techniques/T1573/) Encrypted Channel — Command and Control — observed in 2 of 3 tracked threats
- [T1588](https://attack.mitre.org/techniques/T1588/) Obtain Capabilities — Resource Development — observed in 2 of 3 tracked threats
- [T1595](https://attack.mitre.org/techniques/T1595/) Active Scanning — Reconnaissance — observed in 2 of 3 tracked threats
- [T1005](https://attack.mitre.org/techniques/T1005/) Data from Local System — Collection — observed in 1 of 3 tracked threats
- [T1021](https://attack.mitre.org/techniques/T1021/) Remote Services — Lateral Movement — observed in 1 of 3 tracked threats
- [T1021.001](https://attack.mitre.org/techniques/T1021/001/) Remote Desktop Protocol — Lateral Movement — observed in 1 of 3 tracked threats
- [T1027](https://attack.mitre.org/techniques/T1027/) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 1 of 3 tracked threats
- [T1027.013](https://attack.mitre.org/techniques/T1027/013/) Encrypted/Encoded File — Stealth (formerly Defense Evasion) — observed in 1 of 3 tracked threats
- [T1036](https://attack.mitre.org/techniques/T1036/) Masquerading — Stealth (formerly Defense Evasion) — observed in 1 of 3 tracked threats

## Tracked threats

- [CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass Actively Exploited in SnowLight and AI-Assisted Campaigns](https://intel.threadlinqs.com/threat/TL-2026-1885) — HIGH
- [CitrixBleed 3 — CVE-2026-3055 & CVE-2026-4368 NetScaler ADC/Gateway Memory Overread and Session Hijack](https://intel.threadlinqs.com/threat/TL-2026-0384) — CRITICAL
- [Vshell C2 Framework — Chinese-Language Cobalt Strike Alternative in APT Campaigns (UNC5174/SNOWLIGHT, Operation DRAGONCLONE)](https://intel.threadlinqs.com/threat/TL-2026-0141) — HIGH

## Related CVEs

3 CVEs referenced by tracked UNC5174 activity.

- [CVE-2026-4368](https://intel.threadlinqs.com/cve/CVE-2026-4368)
- [CVE-2026-34486](https://intel.threadlinqs.com/cve/CVE-2026-34486)
- [CVE-2026-3055](https://intel.threadlinqs.com/cve/CVE-2026-3055)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/UNC5174
