UNC2717
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 11:53:22
Targeted industries: government-and-public-sector defense-and-aerospace technology-and-telecommunications
Context
UNC2717 is a threat actor that engages in espionage activities aligned with Chinese government priorities. They demonstrate advanced tradecraft and take measures to avoid detection, making it challenging for network defenders to identify their tools and intrusion methods. UNC2717, along with other Chinese APT actors, has been observed stealing credentials, email communications, and intellectual property. They have targeted global government agencies using malware such as HARDPULSE, QUIETPULSE, and PULSEJUMP.
Reports & references
- internal-fireeye.com — Suspected Apt Actors Leverage Bypass Techniques Pulse Secure Zero Day (report)
- Mandiant — Updates On Chinese Apt Compromising Pulse Secure Vpn Devices (report)