Intrusion setG1048
UNC3886
UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan (APJ) regions. UNC3886 has displayed a deep understanding of edge devices and virtualization technologies through the exploitation of zero-day vulnerabilities and the use of novel malware families and utilities.
- Documented techniques
- 49
- Assessed origin
- China
- Assessed motivation
- Espionage
- First seen
- 2022
- Basis
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.
reconnaissance1
resource development4
initial access1
execution7
persistence4
privilege escalation2
credential access4
discovery4
lateral movement2
collection3
command and control2
defense impairment3
stealth12
- T1014 Rootkit
- T1027.005 Indicator Removal from Tools
- T1036.004 Masquerade Task or Service
- T1070.004 File Deletion
- T1070.006 Timestomp
- T1070.007 Clear Network Connection History and Configurations
- T1078 Valid Accounts
- T1078.001 Default Accounts
- T1205 Traffic Signaling
- T1205.001 Port Knocking
- T1218.011 Rundll32
- T1564.011 Ignore Process Interrupts
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.
CASTLETAPMEDUSAMOPSLEDREPTILERIFLESPINETHINCRUSTVIRTUALPIEVIRTUALPITA
Campaigns
RedPenguin