UNC4841

Aliases: SLIME57

Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:09:20

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

UNC4841 is a well-resourced threat actor that has utilized a wide range of malware and purpose-built tooling to enable their global espionage operations. They have been observed selectively deploying specific malware families at high priority targets, with SKIPJACK being the most widely deployed. UNC4841 primarily targeted government and technology organizations, but they have also been observed targeting other verticals.

Exploited vulnerabilities

  • CVE-2023-2868 (vulnerability)

Reports & references

  • cloud.google.com — Unc4841 Post Barracuda Zero Day Remediation (report)
  • cloud.google.com — Barracuda Esg Exploited Globally (report)
  • i.blackhat.com — Asia 24 Chen Chinese Apt (report)
  • youtube.com — Watch (report)
  • youtube.com — Watch (report)
  • sansorg.egnyte.com — 8Ekljcphpj (report)
  • CISA — Mar 10454006.R3.V1.Clear (report)
  • CISA — Mar 10454006.R2.V1.Clear (report)
  • CISA — Mar 10454006.R1.V2.Clear (report)
  • CISA — Mar 10459736.R1.V1.Clear (report)
  • CISA — Mar 10454006.R4.V2.Clear (report)
  • CISA — Mar 10454006.R5.V1.Clear 0 (report)
  • barracuda.com — Esg Vulnerability (report)
  • mandiant.widen.net — Barracuda Cve 2023 2868 Hardening (report)
  • jsac.jpcert.or.jp — Jsac2025 1 5 Leon Chang Theo Chen En (report)

External references