UNC3886

MITRE ATT&CK: G1048 View on attack.mitre.org

Aliases: UNC3886

First seen
2022-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:05:02

Targeted industries: defense-and-aerospace technology-and-telecommunications

Targeted regions: country_code:us country_code:jp

Context

UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan (APJ) regions. UNC3886 has displayed a deep understanding of edge devices and virtualization technologies through the exploitation of zero-day vulnerabilities and the use of novel malware families and utilities.

Detection coverage

  • 6 YARA rules
  • 772 Sigma rules

Malware & tools used

  • Hypervisor CLI (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Default Accounts (attack-pattern)
  • Compromise Host Software Binary (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Virtual Machine Discovery (attack-pattern)
  • Ignore Process Interrupts (attack-pattern)
  • Malware (attack-pattern)
  • Exploitation for Credential Access (attack-pattern)
  • ESXi Administration Command (attack-pattern)
  • Rundll32 (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Clear Network Connection History and Configurations (attack-pattern)
  • Python (attack-pattern)
  • Abuse Elevation Control Mechanism (attack-pattern)
  • Timestomp (attack-pattern)
  • Prevent Command History Logging (attack-pattern)
  • Archive via Custom Method (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • RC Scripts (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • File Deletion (attack-pattern)
  • Digital Certificates (attack-pattern)
  • Password Managers (attack-pattern)
  • Exploits (attack-pattern)

Reports & references

  • Mandiant — Fortinet Malware Ecosystem (report)
  • Mandiant — Esxi Hypervisors Malware Persistence (report)
  • Mandiant — Vmware Esxi Zero Day Bypass (report)
  • Mandiant — Vmware Detection Containment Hardening (report)
  • MITRE ATT&CK — G1048 (report)
  • cloud.google.com — Vmware Esxi Zero Day Bypass (report)

Attributed from

  • RedPenguin (campaign)

External references