Unknown intruders – likely China-linked spies – have broken into "numerous" enterprise networks since March and deployed backdoors, providing access for their long-term IP and other sensitive data stealing missions, all the while remaining undetected on average for 393 days, according to Google Threat Intelligence. In a paper published today, the threat hunters attribute these network intrusions to UNC5221 and other related suspected Chinese threat groups. UNC5221 has been abusing zero-days in buggy Ivanti gear since at least 2023. Google notes that this UNC crew is separate from Silk Typhoon (aka Hafnium), believed to be behind the December break-in at the US Treasury Department. UNC in Google's threat-group naming taxonomy stands for "Uncategorized," as opposed to FIN (financially motivated) or APT (advanced persistent threat, which means government-backed). [Editor's note: read all about the various security companies' methods for naming cyber crews here... then go bang your head against the wall.] Since March, Google's Mandiant Consulting and incident response team have responded to these UNC5221-related break-ins across legal services, Software as a Service (SaaS) providers, Business Process Outsourcers (BPOs), and technology companies. "The value of these targets extends beyond typical espionage missions, potentially providing data to feed development of zero-days and establishing pivot points for broader access to downstream victims," Google Threat Intelligence wrote. ...
Suspected Chinese spies broke into 'numerous' enterprises
The Register
·Jessica Lyons
·Published Sep 24, 2025
·Updated
Affected Software
1 affected component
Ivanti gear=2023
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses suspected Chinese espionage operations targeting numerous enterprise networks through the deployment of backdoors.
2
What security implications are discussed?
The security implications include unauthorized access to sensitive data and intellectual property potentially stolen by foreign spies.
3
What products or software are affected?
The affected software mentioned in the article is Ivanti Gear, specifically version 2023.
4
How long have these espionage activities been occurring?
The reported espionage activities have been ongoing since March.
5
What is the goal of the intruders in these cyberattacks?
The goal of the intruders is to gain long-term access for stealing intellectual property and sensitive data.