UNC215

First seen
2014-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:10:59

Targeted industries: government-and-public-sector technology-and-telecommunications defense-and-aerospace financial-services media-and-entertainment healthcare-and-pharmaceutical

Targeted regions: country_code:il country_code:sa country_code:ae country_code:gb country_code:fr country_code:de country_code:us country_code:cn

Context

UNC215 is a Chinese nation-state threat actor that has been active since at least 2014. They have targeted organizations in various sectors, including government, technology, telecommunications, defense, finance, entertainment, and healthcare. UNC215 has been observed using tools such as Mimikatz, FOCUSFJORD, and HYPERBRO for initial access and post-compromise activities. They have demonstrated a focus on evading detection and have employed tactics such as using trusted third parties, minimizing forensic evidence, and incorporating false flags. UNC215's targets are located globally, with a particular focus on the Middle East, Europe, Asia, and North America.

Reports & references

  • esentire.com — Ransomware Hackers Attack A Top Safety Testing Org Using Tactics And Techniques Borrowed From Chinese Espionage Groups (report)
  • Mandiant — Unc215 Chinese Espionage Campaign In Israel (report)

External references