NEW: Group Profiler — instant APT intel lookup. Try it →

UNC3886

G1048 China MITRE ATT&CK →

Overview

UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan (APJ) regions. UNC3886 has displayed a deep understanding of edge devices and virtualization technologies through the exploitation of zero-day vulnerabilities and the use of novel malware families and utilities.

Naming & attribution

UNC3886 is tracked under 1 names across the industry. It uses 49 documented ATT&CK techniques — more than 83% of the 174 groups tracked here. Activity attributed since at least 2022.

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1059.012 Hypervisor CLI — used by 1 of 174 groups
  • T1212 Exploitation for Credential Access — used by 1 of 174 groups
  • T1505.006 vSphere Installation Bundles — used by 1 of 174 groups
  • T1548 Abuse Elevation Control Mechanism — used by 1 of 174 groups
  • T1673 Virtual Machine Discovery — used by 1 of 174 groups
  • T1675 ESXi Administration Command — used by 1 of 174 groups
  • T1070.007 Clear Network Connection History and Configurations — used by 2 of 174 groups
  • T1205.001 Port Knocking — used by 2 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • APT5 China — 13 shared techniques (20% overlap)
  • Play — 11 shared techniques (17% overlap)
  • Lazarus Group North Korea — 18 shared techniques (15% overlap)
  • APT41 China — 17 shared techniques (15% overlap)
  • APT3 China — 12 shared techniques (15% overlap)
  • Aquatic Panda China — 11 shared techniques (15% overlap)

Malware families with current indicators

One family attributed to UNC3886, carrying 33 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • Medusa 33 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1190, T1203, T1212
  • Custom malware/implant development — ATT&CK: 8 attributed custom malware families

TTPs — 49 techniques across 13 tactics

Reconnaissance

Resource Development

Initial Access

Credential Access

Lateral Movement

Collection

Command and Control

Tools & malware (8)

MOPSLED · VIRTUALPIE · CASTLETAP · THINCRUST · VIRTUALPITA · REPTILE · MEDUSA · RIFLESPINE

Reporting (2)