Overview 10 indicators
UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan (APJ) regions. UNC3886 has displayed a deep understanding of edge devices and virtualization technologies through the exploitation of zero-day vulnerabilities and the use of novel malware families and utilities.
| ipv4 | 10 | G1048.json |
Techniques 49 ATT&CK
Open in ATT&CK Navigator → or download the layer (49 techniques, layer 4.5)
- T1003.001 LSASS Memory
- T1008 Fallback Channels
- T1014 Rootkit
- T1021.004 SSH
- T1027.005 Indicator Removal from Tools
- T1036.004 Masquerade Task or Service
- T1037 Boot or Logon Initialization Scripts
- T1037.004 RC Scripts
- T1040 Network Sniffing
- T1057 Process Discovery
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1059.004 Unix Shell
- T1059.006 Python
- T1059.012 Hypervisor CLI
- T1068 Exploitation for Privilege Escalation
- T1070.004 File Deletion
- T1070.006 Timestomp
- T1070.007 Clear Network Connection History and Configurations
- T1074.001 Local Data Staging
- T1078 Valid Accounts
- T1078.001 Default Accounts
- T1083 File and Directory Discovery
- T1095 Non-Application Layer Protocol
- T1124 System Time Discovery
- T1190 Exploit Public-Facing Application
- T1203 Exploitation for Client Execution
- T1205 Traffic Signaling
- T1205.001 Port Knocking
- T1212 Exploitation for Credential Access
- T1218.011 Rundll32
- T1505.006 vSphere Installation Bundles
- T1548 Abuse Elevation Control Mechanism
- T1554 Compromise Host Software Binary
- T1555.005 Password Managers
- T1560.001 Archive via Utility
- T1560.003 Archive via Custom Method
- T1564.011 Ignore Process Interrupts
- T1570 Lateral Tool Transfer
- T1587.001 Malware
- T1587.004 Exploits
- T1588.001 Malware
- T1588.004 Digital Certificates
- T1673 Virtual Machine Discovery
- T1675 ESXi Administration Command
- T1681 Search Threat Vendor Data
- T1685 Disable or Modify Tools
- T1686 Disable or Modify System Firewall
- T1690 Prevent Command History Logging
Software 8
Principal sources 6 reports
Ranked by how many of this actor's indicators each report brought in.
- 8bleepingcomputer.com/news/security/chinese-cyberspies-backdo…
- 8cloud.google.com/blog/topics/threat-intelligence/china-n…
- 8censys.com/junos-and-redpenguin
- 8virustotal.com/gui/file/5bef7608d66112315eefff354dae42…
- 2trendmicro.com/en_us/research/25/g/revisiting-unc3886-…
- 2trendmicro.com/content/dam/trendmicro/global/en/resear…
Related groups 1
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 10 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
bleepingcomputer.com/news/security/chinese-cyberspies-backdo… · cloud.google.com/blog/topics/threat-intelligence/china-n… · censys.com/junos-and-redpenguin · virustotal.com/gui/file/5bef7608d66112315eefff354dae42…
101.100.182.122:22 116.88.34.184:22 118.189.188.122:22 129.126.109.50:22 158.140.135.244:22 223.25.78.136:22 45.77.39.28:22 8.222.225.8:22 -
trendmicro.com/en_us/research/25/g/revisiting-unc3886-… · trendmicro.com/content/dam/trendmicro/global/en/resear…
118.193.63.40:22 47.246.68.13:22
Further reading 9
- attack.mitre.org/groups/G1048
- cloud.google.com/blog/topics/threat-intelligence/vmware-…
- mandiant.com/resources/blog/fortinet-malware-ecosyst…
- censys.com/junos-and-redpenguin
- cloud.google.com/blog/topics/threat-intelligence/china-n…
- trendmicro.com/content/dam/trendmicro/global/en/resear…
- virustotal.com/gui/file/5bef7608d66112315eefff354dae42…
- bleepingcomputer.com/news/security/chinese-cyberspies-backdo…
- trendmicro.com/en_us/research/25/g/revisiting-unc3886-…