All threat actors

UNC5221

Alert me

A suspected China-nexus espionage actor known for exploiting Ivanti zero-days and deploying BRICKSTORM on network appliances and virtualization infrastructure. It maintains long dwell times in technology, legal, SaaS, and business-services organizations for strategic intelligence collection.

Also known as

UTA0178

Create a free account to see the reports

Sign in or create a free account to see every report that names UNC5221.

Create free account