news.mlab.sh
Threat intelligence
Threat actor

UNC3886

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
China
First seen
2021-01-01 00:00:00
Motivation
Information theft and espionage
TLP
WHITE

(Mandiant) Following the discovery of malware residing within ESXi hypervisors in September 2022, Mandiant began investigating numerous intrusions conducted by UNC3886, a suspected China-nexus cyber espionage actor that has targeted prominent strategic organizations on a global scale. In January 2023, Mandiant provided detailed analysis of the exploitation of a now-patched vulnerability in FortiOS employed by a threat actor suspected to be UNC3886. In March 2023, we provided details surrounding a custom malware ecosystem utilized on affected Fortinet devices. Furthermore, the investigation uncovered the compromise of VMware technologies, which facilitated access to guest virtual machines. Investigations into more recent operations in 2023 following fixes from the vendors involved in the investigation have corroborated Mandiant's initial observations that the actor operates in a sophisticated, cautious, and evasive nature. Mandiant has observed that UNC3886 employed several layers of organized persistence for redundancy to maintain access to compromised environments over time. Persistence mechanisms encompassed network devices, hypervisors, and virtual machines, ensuring alternative channels remain available even if the primary layer is detected and eliminated.

Also known as

Fire AntUNC3886

Vulnerabilities exploited

Tooling and malware

CASTLETAPMEDUSAMOPSLEDREPTILERIFLESPINETHINCRUSTVIRTUALPIEVIRTUALPITA

MITRE ATT&CK techniques

T1008 Fallback ChannelsT1095 Non-Application Layer ProtocolT1040 Network SniffingT1212 Exploitation for Credential AccessT1685 Disable or Modify ToolsT1686 Disable or Modify System FirewallT1690 Prevent Command History LoggingT1057 Process DiscoveryT1083 File and Directory DiscoveryT1124 System Time DiscoveryT1673 Virtual Machine DiscoveryT1203 Exploitation for Client ExecutionT1675 ESXi Administration CommandT1190 Exploit Public-Facing ApplicationT1570 Lateral Tool TransferT1037 Boot or Logon Initialization ScriptsT1554 Compromise Host Software BinaryT1068 Exploitation for Privilege EscalationT1548 Abuse Elevation Control MechanismT1681 Search Threat Vendor DataT1014 RootkitT1078 Valid AccountsT1205 Traffic Signaling

Coverage 4