UNC3886
UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan (APJ) regions. UNC3886 has displayed a deep understanding of edge devices and virtualization technologies through the exploitation of zero-day vulnerabilities and the use of novel malware families and utilities.
- Known attack methods
- 49
- Origin
- China
- Motive
- Espionage
- First seen
- 2022
- Last seen
- 2025-03
- Source
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, mapped onto the ATT&CK matrix. Each one is a behaviour you can look for in your own logs, and a control you can test.
Reconnaissance
12 techniques · 1 used
Resource Development
9 techniques · 2 used
Initial Access
11 techniques · 1 used
Execution
20 techniques · 3 used
Persistence
22 techniques · 3 used
Privilege Escalation
13 techniques · 2 used
Stealth
30 techniques · 8 used
Defense Impairment
18 techniques · 3 used
Credential Access
17 techniques · 4 used
Discovery
34 techniques · 4 used
Lateral Movement
9 techniques · 2 used
Collection
17 techniques · 2 used
Command and Control
18 techniques · 2 used
Exfiltration
9 techniques
Impact
15 techniques
Reconnaissance1
Resource development4
Initial access1
Execution7
Persistence4
Privilege escalation2
Stealth12
- T1014Rootkit
- T1027.005Indicator Removal from Tools
- T1036.004Masquerade Task or Service
- T1070.004File Deletion
- T1070.006Timestomp
- T1070.007Clear Network Connection History and Configurations
- T1078Valid Accounts
- T1078.001Default Accounts
- T1205Traffic Signaling
- T1205.001Port Knocking
- T1218.011Rundll32
- T1564.011Ignore Process Interrupts
Defense impairment3
Credential access4
Discovery4
Lateral movement2
Collection3
Command and control2
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.