Threat intelligence
- Suspected origin
- China
- First seen
- 2021-01-01 00:00:00
- Motivation
- Information theft and espionage
- TLP
- WHITE
(Mandiant) Following the discovery of malware residing within ESXi hypervisors in September 2022, Mandiant began investigating numerous intrusions conducted by UNC3886, a suspected China-nexus cyber espionage actor that has targeted prominent strategic organizations on a global scale. In January 2023, Mandiant provided detailed analysis of the exploitation of a now-patched vulnerability in FortiOS employed by a threat actor suspected to be UNC3886. In March 2023, we provided details surrounding a custom malware ecosystem utilized on affected Fortinet devices. Furthermore, the investigation uncovered the compromise of VMware technologies, which facilitated access to guest virtual machines.
Investigations into more recent operations in 2023 following fixes from the vendors involved in the investigation have corroborated Mandiant's initial observations that the actor operates in a sophisticated, cautious, and evasive nature. Mandiant has observed that UNC3886 employed several layers of organized persistence for redundancy to maintain access to compromised environments over time. Persistence mechanisms encompassed network devices, hypervisors, and virtual machines, ensuring alternative channels remain available even if the primary layer is detected and eliminated.
Also known as
Fire AntUNC3886
Vulnerabilities exploited
Tooling and malware
CASTLETAPMEDUSAMOPSLEDREPTILERIFLESPINETHINCRUSTVIRTUALPIEVIRTUALPITA
MITRE ATT&CK techniques
T1008 Fallback ChannelsT1095 Non-Application Layer ProtocolT1040 Network SniffingT1212 Exploitation for Credential AccessT1685 Disable or Modify ToolsT1686 Disable or Modify System FirewallT1690 Prevent Command History LoggingT1057 Process DiscoveryT1083 File and Directory DiscoveryT1124 System Time DiscoveryT1673 Virtual Machine DiscoveryT1203 Exploitation for Client ExecutionT1675 ESXi Administration CommandT1190 Exploit Public-Facing ApplicationT1570 Lateral Tool TransferT1037 Boot or Logon Initialization ScriptsT1554 Compromise Host Software BinaryT1068 Exploitation for Privilege EscalationT1548 Abuse Elevation Control MechanismT1681 Search Threat Vendor DataT1014 RootkitT1078 Valid AccountsT1205 Traffic Signaling
Coverage 4
vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three actively exploited vulnerabilities – one in Cisco Secure Firewall Management Center, one in Citrix NetScaler, and one in Fortinet FortiOS –…

vulnerability
Cisco has released a critical security advisory addressing a remote code execution vulnerability (CVE-2026-20212) in its Nexus 9000 switches. An unauthenticated attacker can execute code as root by binding to an unrestri…

threat-intel
This week’s cybersecurity recap highlights a complex landscape of threats, including a Chinese state-sponsored proxy network used for espionage, AI agents causing havoc by discovering vulnerabilities and creating attack…

threat-intel
China-linked cyber espionage group, Fire Ant, has expanded its campaign beyond VMware to compromise Cisco routers and TACACS servers, leveraging a sophisticated toolkit to steal credentials and suppress logging. The grou…
