UNC2717

Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:53:22

Targeted industries: government-and-public-sector defense-and-aerospace technology-and-telecommunications

Context

UNC2717 is a threat actor that engages in espionage activities aligned with Chinese government priorities. They demonstrate advanced tradecraft and take measures to avoid detection, making it challenging for network defenders to identify their tools and intrusion methods. UNC2717, along with other Chinese APT actors, has been observed stealing credentials, email communications, and intellectual property. They have targeted global government agencies using malware such as HARDPULSE, QUIETPULSE, and PULSEJUMP.

Reports & references

  • internal-fireeye.com — Suspected Apt Actors Leverage Bypass Techniques Pulse Secure Zero Day (report)
  • Mandiant — Updates On Chinese Apt Compromising Pulse Secure Vpn Devices (report)

External references