UNC4841
Aliases: SLIME57
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:09:20
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
UNC4841 is a well-resourced threat actor that has utilized a wide range of malware and purpose-built tooling to enable their global espionage operations. They have been observed selectively deploying specific malware families at high priority targets, with SKIPJACK being the most widely deployed. UNC4841 primarily targeted government and technology organizations, but they have also been observed targeting other verticals.
Exploited vulnerabilities
- CVE-2023-2868 (vulnerability)
Reports & references
- cloud.google.com — Unc4841 Post Barracuda Zero Day Remediation (report)
- cloud.google.com — Barracuda Esg Exploited Globally (report)
- i.blackhat.com — Asia 24 Chen Chinese Apt (report)
- youtube.com — Watch (report)
- youtube.com — Watch (report)
- sansorg.egnyte.com — 8Ekljcphpj (report)
- CISA — Mar 10454006.R3.V1.Clear (report)
- CISA — Mar 10454006.R2.V1.Clear (report)
- CISA — Mar 10454006.R1.V2.Clear (report)
- CISA — Mar 10459736.R1.V1.Clear (report)
- CISA — Mar 10454006.R4.V2.Clear (report)
- CISA — Mar 10454006.R5.V1.Clear 0 (report)
- barracuda.com — Esg Vulnerability (report)
- mandiant.widen.net — Barracuda Cve 2023 2868 Hardening (report)
- jsac.jpcert.or.jp — Jsac2025 1 5 Leon Chang Theo Chen En (report)