CARDS
CARDS
Cutting Edge was a campaign conducted by suspected China-nexus espionage actors, variously identified as UNC5221/UTA0178 and UNC5325, that began as early as December 2023 with the exploitation of zero-day vulnerabilities in Ivanti Connect Secure (previously Pulse Secure) VPN appliances. Cutting Edge targeted the U.S. defense industrial base and multiple sectors globally including telecommunications, financial, aerospace, and technology. Cutting Edge featured the use of defense evasion and living-off-the-land (LoTL) techniques along with the deployment of web shells and other custom malware.
Last updated Aug 31, 2026, 6:03 AM EDT
Evidence Boundary
Bottom Line Up Front
Cutting Edge was a campaign conducted by suspected China-nexus espionage actors, variously identified as UNC5221/UTA0178 and UNC5325, that began as early as December 2023 with the exploitation of zero-day vulnerabilities in Ivanti Connect Secure (previously Pulse Secure) VPN appliances. Cutting Edge targeted the U.S. defense industrial base and multiple sectors globally including telecommunications, financial, aerospace, and technology. Cutting Edge featured the use of defense evasion and living-off-the-land (LoTL) techniques along with the deployment of web shells and other custom malware.[1][2][3][4][5][6][7][8]
Potential espionage, credential theft, operational disruption, or data exposure depending on campaign objective.[1][2][3][4][5][6][7][8]
Map local telemetry to the listed ATT&CK techniques before assuming exposure. Review identity, endpoint, network egress, and cloud audit evidence for campaign-specific behavior. Keep attribution and victimology source-bound unless corroborated by local evidence.[1][2][3][4][5][6][7][8]
Decision Summary
Cutting Edge was a campaign conducted by suspected China-nexus espionage actors, variously identified as UNC5221/UTA0178 and UNC5325, that began as early as December 2023 with the exploitation of zero-day vulnerabilities in Ivanti Connect Secure (previously Pulse Secure) VPN appliances. Cutting Edge targeted the U.S. defense industrial base and multiple sectors globally including telecommunications, financial, aerospace, and technology. Cutting Edge featured the use of defense evasion and living-off-the-land (LoTL) techniques along with the deployment of web shells and other custom malware.
The retained record scopes this as apt / nation-state / cybercrime activity during 2023-12-01 to 2024-02-01. Potential espionage, credential theft, operational disruption, or data exposure depending on campaign objective.[1][2][3][4][5][6][7][8]
Map local telemetry to the listed ATT&CK techniques before assuming exposure. Review identity, endpoint, network egress, and cloud audit evidence for campaign-specific behavior. Keep attribution and victimology source-bound unless corroborated by local evidence.[1][2][3][4][5][6][7][8]
Confirmed reporting is separated from attribution, victim, and prevalence claims that the retained sources do not establish. Confidence: High for MITRE-tracked campaign metadata and ATT&CK relationships; operational currentness should be validated..[1][2][3][4][5][6][7][8]
Actor Mapping
Targeting
Tradecraft
Tools / Observables
Source Reconciliation
Campaign rows are retained as source-backed context. Actor mappings do not automatically merge actor records; SOCRadar, MITRE, Mandiant, CrowdStrike, Microsoft, and other future sources can disagree on boundaries, aliases, or campaign ownership.
Campaign row is compressed for directory seeding. Confirm actor linkage, infrastructure, and targeting with source-specific reports and local telemetry.
IntelliOS
None Found
Citations