NEW: Group Profiler — instant APT intel lookup. Try it →
Emblem illustrating the UNC3886 threat group

UNC3886

G1048 China MITRE ATT&CK →

Overview

UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan (APJ) regions. UNC3886 has displayed a deep understanding of edge devices and virtualization technologies through the exploitation of zero-day vulnerabilities and the use of novel malware families and utilities.

Naming & attribution

It uses 49 documented ATT&CK techniques — more than 83% of the 174 groups tracked here. Activity attributed since at least 2022.

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1059.012 Hypervisor CLI — used by 1 of 174 groups
  • T1212 Exploitation for Credential Access — used by 1 of 174 groups
  • T1505.006 vSphere Installation Bundles — used by 1 of 174 groups
  • T1548 Abuse Elevation Control Mechanism — used by 1 of 174 groups
  • T1673 Virtual Machine Discovery — used by 1 of 174 groups
  • T1675 ESXi Administration Command — used by 1 of 174 groups
  • T1070.007 Clear Network Connection History and Configurations — used by 2 of 174 groups
  • T1205.001 Port Knocking — used by 2 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • APT5 China — 13 shared techniques (20% overlap)
  • Play — 11 shared techniques (17% overlap)
  • Lazarus Group North Korea — 18 shared techniques (15% overlap)
  • APT41 China — 17 shared techniques (15% overlap)
  • APT3 China — 12 shared techniques (15% overlap)
  • Aquatic Panda China — 11 shared techniques (15% overlap)

Malware families with tracked indicators

One family attributed to UNC3886, with 46 deduplicated indicators observed across abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL over the corpus's window (up to three years, as of 2026-09-27). MITRE documents what a group does; these are the indicators its malware families have surfaced in that window.

  • Medusa 46 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1190, T1203, T1212
  • Custom malware/implant development — ATT&CK: 8 attributed custom malware families

TTPs — 49 techniques across 13 tactics

Reconnaissance

Resource Development

Initial Access

Credential Access

Lateral Movement

Collection

Command and Control

Tools & malware (8)

MOPSLED · VIRTUALPIE · CASTLETAP · THINCRUST · VIRTUALPITA · REPTILE · MEDUSA · RIFLESPINE

Reporting (2)