← All actors Recent activity

UNC3886 G1048

UNC3886 · castletap · mopsled · redpenguin · riflespine · tinyshell

Indicators
10
Source reports
6
Activity span
not dated
Newest indicator
unknown
Upstream change
2026-01-02

Overview 10 indicators

UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan (APJ) regions. UNC3886 has displayed a deep understanding of edge devices and virtualization technologies through the exploitation of zero-day vulnerabilities and the use of novel malware families and utilities.

ipv410G1048.json

Techniques 49 ATT&CK

Open in ATT&CK Navigator → or download the layer (49 techniques, layer 4.5)

Software 8

Principal sources 6 reports

Ranked by how many of this actor's indicators each report brought in.

What the sources have in common — not a claim that these are the same actor. See the whole graph.

Timeline 10 indicators

Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.

  1. or earlier 8 ipv4this year

    bleepingcomputer.com/news/security/chinese-cyberspies-backdo… · cloud.google.com/blog/topics/threat-intelligence/china-n… · censys.com/junos-and-redpenguin · virustotal.com/gui/file/5bef7608d66112315eefff354dae42…

    101.100.182.122:22
    116.88.34.184:22
    118.189.188.122:22
    129.126.109.50:22
    158.140.135.244:22
    223.25.78.136:22
    45.77.39.28:22
    8.222.225.8:22

  2. or earlier 2 ipv4this year

    trendmicro.com/en_us/research/25/g/revisiting-unc3886-… · trendmicro.com/content/dam/trendmicro/global/en/resear…

    118.193.63.40:22
    47.246.68.13:22

Further reading 9