UNC5174
Reports
4
First seen
Nov 1, 2025
Last seen
Jul 7, 2026
Motivation
Espionage, Financial
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Victim regions
United States ×1
Top ATT&CK techniques
T1190 Exploit Public-Facing Application ×4T1566 Phishing ×3T1070.001 Indicator Removal: Clear Windows Event Logs ×2T1555 Credentials from Password Stores ×2T1505.003 Web Shell ×2T1003 OS Credential Dumping ×2T1486 Data Encrypted for Impact ×2T1087 Account Discovery ×1T1021 Remote Services ×1T1219 Remote Access Software ×1T1543 Create or Modify System Process ×1T1071 Application Layer Protocol ×1
Indicators
filename ×39hash_sha256 ×31url ×13ip_v4 ×10domain ×9cve ×7
Indicator values are available on Pro and via the API.
Associated CVEs
Recent reports
Critical