UNC2630

Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:53:20

Targeted industries: government-and-public-sector technology-and-telecommunications defense-and-aerospace

Targeted regions: country_code:us country_code:cn country_code:jp

Context

UNC2630 is a threat actor believed to be affiliated with the Chinese government. They engage in cyber espionage activities, targeting organizations aligned with Beijing's strategic objectives. UNC2630 demonstrates advanced tradecraft and employs various malware families, including SLOWPULSE and RADIALPULSE, to compromise Pulse Secure VPN appliances. They also utilize modified binaries and scripts to maintain persistence and move laterally within compromised networks.

Reports & references

  • internal-fireeye.com — Suspected Apt Actors Leverage Bypass Techniques Pulse Secure Zero Day (report)
  • Mandiant — Updates On Chinese Apt Compromising Pulse Secure Vpn Devices (report)

External references