Indicators are what attackers leave behind. Stolen credentials are what they arrive with.
espionageThreat Actor
Active Threat
UNC5174
64
IOCs Tracked
2
Intel Reports
Associated IOCs50 total
IP19
156.59.13.38221.2.22.14527.210.0.13174.125.196.11327.150.112.38103.56.52.6127.219.79.22638.181.79.1527.150.113.127.150.114.115123.132.37.188119.165.225.12927.199.77.113103.56.52.142148.66.16.22627.150.113.18327.210.226.25439.85.164.6103.215.77.214Domain11
microsoft-defend.club2026-10-09High
microsoft-symantec.art2026-10-09High
micrcs.microsoft-defend.club2026-10-09High
catserver.properties2026-10-09High
e.md2026-10-09High
cfcert.store2026-10-09High
sqlmap.py2026-10-09High
id_rsa.pub2026-10-09High
encoding.default.ge2026-10-09High
gost.x64.so2026-10-09High
catserver.store2026-10-09High
URL11
http://microsoft-symantec.art:8848/sl2026-10-09High
http://103.215.77.214:8080/3.asmx2026-10-09High
http://microsoft-symantec.art:8848/swt2026-10-09High
http://microsoft-symantec.art:8848/?h=microsoft-symantec.art&p=8848&t=tcp&a=w64&stage=true2026-10-09High
http://microsoft-symantec.art:8848/slt2026-10-09High
http://microsoft-symantec.art:8848/?h=microsoft-symantec.art&p=8848&t=tcp&a=w32&stage=true2026-10-09High
http://victm.edu.vn/3.asmx/Tas9er2026-10-09High
http://baidu.com2026-10-09High
https://ctrlaltintel.com/research/china-vietnam-campaign/2026-10-09High
symantec.art:8848/slt2026-10-09High
edu.vn:80/2026-10-09High
MD57
1415c48ad7d8848191b0cd7a122a7cfb2026-10-09High
c82698395e6a30cad74c0bc0a6cd51af2026-10-09High
f5de3ac3f12a2eee62a58d7ec77693dd2026-10-09High
bed7058beeeefc3efeb8b408ec68e5fa2026-10-09High
2058842e1799195a2f3c9971e4dea24e2026-10-09High
40b96d9df310d5f448c0908c3231ff4e2026-10-09High
64aa88125366a1787919b5ec61befa1d2026-10-09High
SHA2561
4a74676bd00250d9b905b95c75c067369e3911cdf3141f947de517f58fc9f85cCVE1
CVE-2025-551822026-10-10High
Threat Profile
Motivationespionage
Last seenOct 2026
IOCs tracked64