Cyber Threat Report: 'Bringing Access Back — Initial Access Brokers Exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect'

Report Author Mandiant
Publication Date 2024-03-21
Original Reporting Source
Attributed to Nation China
Related Intrusion Sets UNC5174
Related Threat Actors Chinese Ministry of State Security
Identified CVEs CVE-2023-46747 , CVE-2024-1709 , CVE-2024-1708
Victim Sectors National Government, Education, Non Profit

This blog post by researchers at Mandiant describes how the threat actor UNC5174 exploited vulnerabilities in F5 BIG-IP appliances and Connectwise ScreenConnect, affecting numerous institutions, primarily in the U.S. and Canada. UNC5174 is believed to be a former Chinese hacktivist now acting as a contractor for China's Ministry of State Security, focusing on access operations. Researchers observed intrusions against Southeast Asian and U.S. research and education institutions, Hong Kong businesses, NGOs, and U.S. and UK government organizations. The post includes Indicators of Compromise (IOCs), MITRE ATT&CK techniques and remediation / hardening recommendations.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph

Mitigations to defend against the techniques in this report

Identified MITRE ATT&CK Techniques