Overview
Cutting Edge (MITRE ATT&CK ID C0029) was a campaign conducted by suspected China-nexus espionage actors, variously identified as UNC5221/UTA0178 and UNC5325, per MITRE’s campaign profile. MITRE documents the campaign as beginning as early as December 2023 with the exploitation of zero-day vulnerabilities in Ivanti Connect Secure (previously Pulse Secure) VPN appliances, targeting the US defense industrial base and multiple sectors globally, including telecommunications, financial, aerospace, and technology. MITRE notes the campaign featured defense evasion and living-off-the-land (LOTL) techniques alongside the deployment of web shells and other custom malware.
Timeline
Per MITRE ATT&CK’s ingested data, this campaign’s documented activity window runs from December 2023 to February 2024.
Tools involved (per MITRE ATT&CK relationship data)
MITRE ATT&CK’s relationship data for this campaign does not link a single formally tracked group entity (consistent with the multiple cluster designations — UNC5221/UTA0178 and UNC5325 — noted in MITRE’s description), but documents an extensive custom malware set specific to this campaign: WARPWIRE, LITTLELAMB.WOOLTEA, PITSTOP, WIREFIRE, ZIPLINE, BUSHWALK, FRAMESTING, GLASSTOKEN, and LIGHTWIRE, alongside CrackMapExec and Impacket.
What we don’t have
MITRE’s own attribution language (“suspected China-nexus”) and its use of two distinct unnamed-cluster designations (UNC5221/UTA0178, UNC5325) reflects incomplete attribution consensus, not a confirmed single group. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle.
Frequently Asked Questions
What was Cutting Edge? A campaign, per MITRE ATT&CK, by suspected China-nexus actors exploiting Ivanti Connect Secure VPN zero-days from December 2023, targeting the US defense industrial base and multiple global sectors.
Which vulnerabilities did Cutting Edge exploit? MITRE’s campaign description references zero-day vulnerabilities in Ivanti Connect Secure (formerly Pulse Secure) VPN appliances, without naming specific CVE IDs in our ingested campaign-level data.
Is Cutting Edge attributed to a named threat group? Not to a single formally tracked MITRE ATT&CK group — MITRE’s description cites two distinct cluster designations (UNC5221/UTA0178 and UNC5325) rather than one confirmed actor.
Data sourced from MITRE ATT&CK® (https://attack.mitre.org), campaign ID C0029, aggregated September 12, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more campaign profiles.