Activity timeline
UTA0178 appears in 4 tracked threats between and ; the busiest month was 2026-04 with 3 reports.
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 4 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 4 of 4 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 4 of 4 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 4 of 4 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 4 of 4 tracked threats
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 4 of 4 tracked threats
- T1505 Server Software Component — Persistenceobserved in 4 of 4 tracked threats
- T1070 Indicator Removal — Stealth (formerly Defense Evasion)observed in 3 of 4 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 3 of 4 tracked threats
- T1090 Proxy — Command and Controlobserved in 3 of 4 tracked threats
- T1547 Boot or Logon Autostart Execution — Persistenceobserved in 3 of 4 tracked threats
- T1572 Protocol Tunneling — Command and Controlobserved in 3 of 4 tracked threats
- T1685 Disable or Modify Tools — Defense Impairmentobserved in 3 of 4 tracked threats
- T1020 Automated Exfiltration — Exfiltrationobserved in 2 of 4 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 2 of 4 tracked threats
Tracked threats
- BRICKSTORM Backdoor: UNC5221 PRC-Nexus APT Targeting VMware vSphere InfrastructureCRITICAL
- F5 BIG-IP APM Unauthenticated Remote Code Execution via Stack Buffer Overflow (CVE-2025-53521) — CISA KEV Active Exploitation by Chinese Nation-State ActorCRITICAL
- CVE-2025-53521: F5 BIG-IP APM Unauthenticated Remote Code Execution via Stack-based Buffer OverflowCRITICAL
- CVE-2025-53521: F5 BIG-IP APM Unauthenticated Remote Code Execution via apmd Process — Active Exploitation by UNC5221 (BRICKSTORM)CRITICAL