49
Techniques
8
Toolsets
3
CVEs Referenced
1
KEV Entries
CISA Known Exploited
About UNC3886

UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan (APJ) regions. UNC3886 has displayed a deep understanding of edge devices and virtualization technologies through the exploitation of zero-day vulnerabilities and the use of novel malware families and utilities.

View MITRE record ↗

Techniques by Tactic (49)
Toolsets (8)
🐛
CASTLETAP S1224
Malware · Network Devices
🐛
MEDUSA S1220
Malware · Linux
🐛
MOPSLED S1221
Malware · Linux
🐛
REPTILE S1219
Malware · Linux
🐛
Malware · Linux
🐛
THINCRUST S1223
Malware · Network Devices
🐛
Malware · ESXi
🐛
Malware · ESXi, Linux
CVEs Referenced (3 · 1 CISA KEV)
CVE-2014-7169View full details on NVDKEV
CVE-2016-6662View full details on NVD
CVE-2019-3610View full details on NVD
↑