UNC3886 — APT Profile
UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan (APJ) regions. UNC3886 has displayed a deep understanding of edge devices and virtualization technologies through the exploitation of zero-day vulnerabilities and the use of novel malware families and utilities.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Tools & malware
- CASTLETAP Backdoor
- MEDUSA Ransomware
- MOPSLED Backdoor
- REPTILE Rootkit
- RIFLESPINE Backdoor
- THINCRUST Backdoor
- VIRTUALPIE Backdoor
- VIRTUALPITA Backdoor
Vendor research
- Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation Marvi, A. et al.
- VMware ESXi Zero-Day Used by Chinese Espionage Actor to Perform Privileged Guest Operations on Compromised Hypervisors Google Cloud
- Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation Mandiant
Countries linked to this actor
- Singapore targets