UNC6201
- First seen
- 2026-03-15 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Last IoC activity
- 2026-06-08 12:56:24
- Profile updated
- 2026-07-07 12:25:26
Targeted industries: government-and-public-sector technology-and-telecommunications energy-and-utilities
Targeted regions: country_code:us country_code:au country_code:ca
Context
UNC6201 is a sophisticated Chinese state-sponsored hacking group that exploited CVE-2026–22769, a critical vulnerability in Dell RecoverPoint for Virtual Machines appliances, to establish a persistent presence. They deployed a permanent backdoor using techniques like Single Packet Authorization and "Port Knocking." Unlike typical hackers who conceal their activities within the Operating System, UNC6201 operated at the Virtualization Layer to avoid detection.
Reports & references
- cloud.google.com — Unc6201 Exploiting Dell Recoverpoint Zero Day (report)