Threadlinqs IntelligenceStart free

Threat actorChinaTracked since 2026-02

UNC5221

Also known as:Red Dev 61Warp PandaUTA0178Silk TyphoonEmissary PandaHAFNIUMOperation Exchange MarauderPROSPERO OOO operator

As of 2026-07-19, UNC5221 is a China-nexus threat actor tracked by Threadlinqs Intelligence across 6 threats spanning apt, malware, vulnerability. Also known as Red Dev 61, Warp Panda, UTA0178, Silk Typhoon. ATT&CK coverage spans 75 techniques across 15 tactics in 6 of 6 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1059 (Command and Scripting Interpreter), T1190 (Exploit Public-Facing Application).

Tracked threats
66 critical
First seen
2026-02-16
Last seen
2026-06-07
ATT&CK techniques
75across 6 of 6 threats
Related CVEs
5Referenced by its activity
Attribution
ChinaNation or origin
Nation: China · 6 tracked threat(s) · Categories: APT, MALWARE, VULNERABILITY

Activity timeline

UNC5221 appears in 6 tracked threats between and ; the busiest month was 2026-04 with 3 reports.

ATT&CK techniques observed

75 techniques observed across 6 of 6 tracked threats · Command and Control (10), Stealth (formerly Defense Evasion) (9), Persistence (8), Discovery (7), Resource Development (7), Credential Access (6)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 6 of 6 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 6 of 6 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 6 of 6 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 5 of 6 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 5 of 6 tracked threats
  • T1505 Server Software Component — Persistenceobserved in 5 of 6 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 4 of 6 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 4 of 6 tracked threats
  • T1090 Proxy — Command and Controlobserved in 4 of 6 tracked threats
  • T1572 Protocol Tunneling — Command and Controlobserved in 4 of 6 tracked threats
  • T1685 Disable or Modify Tools — Defense Impairmentobserved in 4 of 6 tracked threats
  • T1021 Remote Services — Lateral Movementobserved in 3 of 6 tracked threats
  • T1070 Indicator Removal — Stealth (formerly Defense Evasion)observed in 3 of 6 tracked threats
  • T1078 Valid Accounts — Privilege Escalationobserved in 3 of 6 tracked threats
  • T1543 Create or Modify System Process — Persistenceobserved in 3 of 6 tracked threats

Tracked threats

Related CVEs

5 CVEs referenced by tracked UNC5221 activity