Activity timeline
UNC5221 appears in 6 tracked threats between and ; the busiest month was 2026-04 with 3 reports.
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 6 of 6 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 6 of 6 tracked threats
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 6 of 6 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 5 of 6 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 5 of 6 tracked threats
- T1505 Server Software Component — Persistenceobserved in 5 of 6 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 4 of 6 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 4 of 6 tracked threats
- T1090 Proxy — Command and Controlobserved in 4 of 6 tracked threats
- T1572 Protocol Tunneling — Command and Controlobserved in 4 of 6 tracked threats
- T1685 Disable or Modify Tools — Defense Impairmentobserved in 4 of 6 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 3 of 6 tracked threats
- T1070 Indicator Removal — Stealth (formerly Defense Evasion)observed in 3 of 6 tracked threats
- T1078 Valid Accounts — Privilege Escalationobserved in 3 of 6 tracked threats
- T1543 Create or Modify System Process — Persistenceobserved in 3 of 6 tracked threats
Tracked threats
- VerdantBamboo (UNC5221 / WARP PANDA) BRICKSTORM Campaign — MSP Supply-Chain Compromise of Edge Appliances with 18-Month DwellCRITICAL
- BRICKSTORM Backdoor: UNC5221 PRC-Nexus APT Targeting VMware vSphere InfrastructureCRITICAL
- F5 BIG-IP APM Unauthenticated Remote Code Execution via Stack Buffer Overflow (CVE-2025-53521) — CISA KEV Active Exploitation by Chinese Nation-State ActorCRITICAL
- CVE-2025-53521: F5 BIG-IP APM Unauthenticated Remote Code Execution via Stack-based Buffer OverflowCRITICAL
- CVE-2025-53521: F5 BIG-IP APM Unauthenticated Remote Code Execution via apmd Process — Active Exploitation by UNC5221 (BRICKSTORM)CRITICAL
- Ivanti EPMM Dual-CVE Unauthenticated RCE Chain (CVE-2026-1281 + CVE-2026-1340) — CVSS 9.8, CISA KEV, Dutch Government Breached, Bulletproof Hosting IAB, Sleeper Webshells, 28K+ Attacking IPsCRITICAL