Home/Threat Actor/UNC3886
Threat Actor

UNC3886

unc3886 · china_state_sponsored_mandiant_unc3886_virtualization_firewall_zero_day_specialist · active since 2021-09

UNC3886 is Mandiant's canonical designation for a Chinese state-sponsored cyber espionage group specializing in zero-day exploitation of virtualization platforms (VMware ESXi + vCenter) and firewall appliances (FortiOS / FortiGate) that traditionally lack endpoint detection and response (EDR) solutions per Mandiant canonical assessment ("UNC3886 is a highly adept Chinese cyber espionage group that has targeted and exploited zero-day vulnerabilities in firewall and virtualization technologies, which do not support EDR solutions. UNC3886 has primarily targeted defense, technology, and telecommunication organizations located in the US and APJ regions"); Chinese state-sponsored attribution via Mandiant canonical UNC3886 designation (late 2022 + ongoing tracking through 2024) + extensive custom malware ecosystem analysis + Mandiant VMware ESXi zero- day blog canonical CVE-2023-20867 coverage + Mandiant Stealth Mode blog Chinese Cyber Espionage Actors Continue to Evolve Tactics canonical coverage + Mandiant Cutting Edge Part 3 Ivanti investigation canonical UNC3886/UNC5325 association + VMware June 2023 canonical CVE-2023-20867 security advisory + TechTarget Alex Marvi Mandiant consultant canonical UNC3886 VMware ESXi coverage + SecurityWeek + SC Media + Security Brief Asia + Hacker News + Security Boulevard industry coverage.

standalone cluster paralleling apt5_unc2630 + unc4841 + unc5325 in v0.1.175 Mandiant UNC Chinese-state-sponsored network-edge- appliance zero-day specialist cluster cell; operational target profile signature defense industrial base + technology + telecommunication organizations primary per Mandiant + signature US + Asia-Pacific-Japan (APJ) regions geographic distribution + signature VMware ESXi + vCenter Server + FortiGate firewall operator target population + signature edge-platforms-without- EDR-coverage strategic platform selection; operational attack architecture: (1) cluster- defining VMware ESXi + vCenter zero-day specialization with VIRTUALPITA + VIRTUALPIE custom backdoors disclosed late 2022 + CVE-2023- 20867 authentication bypass June 2023 + CVE-2023- 34048 vCenter Server out-of-bounds write zero-day; (2) cluster-defining FortiOS / FortiGate firewall zero-day specialization with THINCRUST + CASTLETAP + TABLEFLIP + REPTILE-derived malware families + CVE-2022-41328 path traversal March 2023 exploitation enabling Fortinet-to-vCenter pivot tradecraft.

(3) cluster-defining CVE- 2023-20867 VMware ESXi authentication bypass zero-day enabling execution of privileged commands across Windows + Linux + PhotonOS (vCenter) guest VMs without authentication of guest credentials from compromised ESXi host with no default logging on guest VMs.

(4) cluster- defining CVE-2022-41328 FortiOS path traversal zero-day allowing overwrite of legitimate files in normally restricted system directory.

(5) cluster-defining CVE-2023-34048 vCenter Server out-of-bounds write zero-day leveraging access to compromised ESXi hosts.

(6) cluster-defining extensive custom malware ecosystem with VIRTUALPITA + VIRTUALPIE VMware ESXi backdoors + THINCRUST + CASTLETAP + TABLEFLIP FortiGate backdoors + REPTILE Linux rootkit + DRIEDMOAT additional backdoor with embedded certificate stolen from compromised appliance for C2 encryption + FOXTROT REPTILE-modified malware; (7) cluster-defining CASTLETAP magic-packet activation tradecraft with passive listening for magic packets that activate backdoor functionality + SSL-encrypted C2 connection-back; (8) cluster-defining EDR-evasion via edge- platform-non-EDR targeting strategy per Mandiant ("continues to target devices and platforms that traditionally lack EDR endpoint detection and response solutions and make use of zero-day exploits on those platforms") establishing strategic platform-selection methodology distinct from Windows-endpoint- focused clusters.

(9) cluster-defining indicator-replacement-under-one-week anti-forensic tradecraft per Mandiant VMware ESXi blog ("this particular attacker has been observed replacing indicators mentioned in publications in under a week after their release")

(10) cluster-defining vpxuser service account credential harvesting via vPostgreSQL database embedded in vCenter Server Appliance with e.py Python script for vpxuser credentials + guest VM command execution.

(11) cluster-defining UNC3886-UNC5325 moderate-confidence Ivanti association per Mandiant February 2024 ("Mandiant identified TTPs and malware code overlaps in LITTLELAMB.WOOLTEA and PITHOOK with malware leveraged by UNC3886. Mandiant assesses with moderate confidence that UNC5325 is associated with UNC3886")

(12) cluster- defining UNC3886-UNC5221 (Silk Typhoon) TTP overlap signature per Mandiant cross-cluster tracking, UNC5221 curated in corpus as silk_typhoon.yaml.

(13) signature anti-forensic file system verification disable on startup + log clearing + modified logs detection evasion; (14) signature stolen certificate embedded in backdoor C2 encryption signature.

(15) signature DRIEDMOAT passive backdoor with embedded certificate stolen from compromised appliance mirroring REPTILE/SEASPY/CASTLETAP design; cluster fills the Mandiant-UNC3886-Chinese-state- sponsored + VMware-ESXi-vCenter-zero-day- specialist + FortiOS-FortiGate-firewall-zero-day- specialist + CVE-2023-20867-VMware-ESXi-auth- bypass + CVE-2022-41328-FortiOS-path-traversal + CVE-2023-34048-vCenter-Server + VIRTUALPITA- VIRTUALPIE-THINCRUST-CASTLETAP-TABLEFLIP-REPTILE- DRIEDMOAT-custom-malware-ecosystem + defense- industrial-base-technology-telecommunication- multi-sector + US-APJ-geographic-distribution + EDR-evasion-edge-platform-non-EDR-targeting + indicator-replacement-under-one-week-anti- forensic + UNC3886-UNC5325-moderate-confidence- association + UNC3886-UNC5221-Silk-Typhoon-TTP- overlap + vpxuser-credential-harvesting-vPostgreSQL position in Mandiant UNC Chinese-state-sponsored network-edge-appliance zero-day specialist cluster cell.

canonical illustration of Chinese state-sponsored VMware ESXi + FortiOS zero-day specialist + EDR-evasion via edge-platform-non- EDR targeting strategy + extensive custom malware ecosystem + indicator-replacement-under-one-week anti-forensic tradecraft + UNC3886-UNC5325- moderate-confidence Ivanti association + UNC3886- UNC5221 Silk Typhoon TTP overlap cited in essentially all subsequent Chinese-state- sponsored virtualization-and-firewall-appliance industry analyses through 2022-2026 period.

china_state_sponsored_mandiant_unc3886_virtualization_firewall_zero_day_specialist confidence: high 21 aliases MITRE ATT&CK G1048 ↗
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited3

Profile

UNC3886 is Mandiant's canonical designation for a Chinese state-sponsored cyber espionage group specializing in zero-day exploitation of virtualization platforms (VMware ESXi + vCenter) + firewall appliances (FortiOS / FortiGate) that traditionally lack EDR solutions. Chinese state-sponsored attribution via Mandiant canonical UNC3886 designation + extensive custom malware ecosystem analysis + multiple Mandiant blog disclosures (late 2022 + March 2023 + June 2023 + March 2024). Standalone cluster paralleling apt5_unc2630 + unc4841 + unc5325 in v0.1.175 Mandiant UNC Chinese-state-sponsored network-edge-appliance zero-day specialist cell.

Operational target profile
  • Defense industrial base + technology + telecommunication primary per Mandiant.
  • US + APJ (Asia-Pacific-Japan) geographic distribution.
  • VMware ESXi + vCenter operators signature.
  • FortiGate firewall operators signature.
  • Edge platforms without EDR coverage strategic selection Operational attack architecture: (1) VMware ESXi + vCenter zero-day specialization (cluster-defining) (2) FortiOS / FortiGate firewall zero-day specialization (cluster-defining) (3) CVE-2023-20867 VMware ESXi auth bypass (cluster-defining) (4) CVE-2022-41328 FortiOS path traversal (cluster-defining) (5) CVE-2023-34048 vCenter Server out-of-bounds write (cluster-defining) (6) VIRTUALPITA + VIRTUALPIE + THINCRUST + CASTLETAP + TABLEFLIP + REPTILE + DRIEDMOAT custom malware ecosystem (cluster-defining) (7) EDR-evasion via edge-platform-non-EDR targeting strategy (cluster-defining) (8) Indicator-replacement-under-one-week anti- forensic tradecraft (cluster-defining) (9) vpxuser credential harvesting via vPostgreSQL database (cluster-defining) (10) UNC3886-UNC5325 moderate-confidence Ivanti association + UNC3886-UNC5221 (Silk Typhoon) TTP overlap (cluster-defining) The cluster fills the Mandiant-UNC3886-Chinese- state-sponsored + VMware-ESXi-vCenter-zero-day- specialist + FortiOS-FortiGate-firewall-zero-day- specialist + CVE-2023-20867-VMware-ESXi-auth- bypass + CVE-2022-41328-FortiOS-path-traversal + CVE-2023-34048-vCenter-Server + VIRTUALPITA- VIRTUALPIE-THINCRUST-CASTLETAP-TABLEFLIP-REPTILE- DRIEDMOAT-custom-malware-ecosystem + defense- industrial-base-technology-telecommunication- multi-sector + US-APJ-geographic-distribution + EDR-evasion-edge-platform-non-EDR-targeting + indicator-replacement-under-one-week-anti- forensic + UNC3886-UNC5325-moderate-confidence- association + UNC3886-UNC5221-Silk-Typhoon-TTP- overlap + vpxuser-credential-harvesting-vPostgreSQL position in Mandiant UNC Chinese-state-sponsored network-edge-appliance zero-day specialist cluster cell.

Aliases

21
unc3886unc 3886mandiant unc3886 trackingunc3886 chinese cyber espionage groupunc3886 prc china-nexus espionage actorunc3886 vmware esxi specialistunc3886 vcenter server specialistunc3886 fortinet fortios firewall specialistunc3886 virtualization platform zero-day specialistunc3886 cve-2023-20867 vmware esxi auth bypassunc3886 cve-2022-41328 fortios path traversalunc3886 cve-2023-34048 vcenter serverunc3886 virtualpita virtualpie thincrust castletap tableflip reptile driedmoatunc3886 defense industrial base technology telecommunication targetingunc3886 us apj asia-pacific japan regions targetingunc3886 edr-evasion edge-platform-non-edr targeting strategyunc3886 highly-adept-tradecraft mandiant assessmentunc3886 indicator-replacement-under-one-week tradecraftunc3886 vpxuser credential harvesting vpostgresql databaseunc3886 unc5325 ivanti moderate-confidence associationunc3886 unc5221 silk typhoon ttp overlap

Notable Campaigns

10
2024UNC3886-UNC5325 Moderate-Confidence Ivanti Association February 2024
2024UNC3886-UNC5221 (Silk Typhoon) TTP Overlap Signature
2023UNC3886 CVE-2022-41328 FortiOS Path Traversal Zero-Day Exploitation March 2023
2023UNC3886 CVE-2023-20867 VMware ESXi Authentication Bypass June 2023
2023UNC3886 vpxuser Credential Harvesting via vPostgreSQL Database Signature
2023UNC3886 CVE-2023-34048 vCenter Server Out-of-Bounds Write Zero-Day
2022-2026Continued Industry Reference Status (2022-2026)
2022-2024UNC3886 EDR-Evasion via Edge-Platform-Non-EDR Targeting Strategy Signature
2022-2024UNC3886 Indicator-Replacement-Under-One-Week Anti-Forensic Tradecraft Signature
2022UNC3886 Origin, Late 2022 VMware ESXi Novel Malware Disclosure

Attribution & Reporting

Attributed by
Mandiant (canonical UNC3886 designation late 2022 + ongoing tracking through 2024)Mandiant Stealth Mode blog (canonical Stealth Mode Chinese Cyber Espionage Actors coverage)Mandiant VMware ESXi zero-day blog (canonical CVE-2023-20867 coverage)VMware (canonical CVE-2023-20867 security advisory June 2023)TechTarget / Alex Marvi / Mandiant consultant (canonical UNC3886 VMware ESXi coverage June 2023)SecurityWeek (canonical UNC3886/UNC5325 link coverage Feb 2024)SC Media (canonical Ivanti attacks linked to espionage group coverage)Security Brief Asia (canonical UNC3886/UNC5325 association coverage)The Hacker News (canonical Chinese Hackers Exploiting Ivanti VPN Flaws coverage)Security Boulevard (canonical CISA/Mandiant warn worsening Ivanti situation coverage)
Key reporting
reportMandiant (late 2022): canonical UNC3886 VMware ESXi novel malware system disclosure
reportMandiant (June 2023): VMware ESXi Zero-Day Used by Chinese Espionage Actor, CVE-2023-20867 canonical
reportMandiant Stealth Mode (March 2024): Chinese Cyber Espionage Actors Continue to Evolve Tactics to Avoid Detection
reportMandiant Cutting Edge Part 3 (March 2024): Investigating Ivanti Connect Secure VPN Exploitation, UNC3886/UNC5325 association
reportVMware (June 2023): canonical CVE-2023-20867 security advisory
reportTechTarget / Alex Marvi (June 2023): canonical UNC3886 VMware ESXi coverage
reportSecurityWeek (Feb 2024): canonical UNC3886/UNC5325 Ivanti coverage
reportSC Media / Ivanti attacks linked to espionage group: canonical
reportSecurity Brief Asia: canonical Mandiant UNC5325 cyber attacks on Ivanti devices
reportThe Hacker News (Feb 2024): canonical Chinese Hackers Exploiting Ivanti VPN Flaws
reportSecurity Boulevard (March 2024): canonical CISA/Mandiant Worsening Ivanti Situation

Operational

State sponsor

UNC3886 is Mandiant's canonical designation for a Chinese state-sponsored cyber espionage group specializing in zero-day exploitation of virtualization platforms (VMware ESXi + vCenter) + firewall appliances (FortiOS / FortiGate) that traditionally lack endpoint detection and response (EDR) solutions. Per Mandiant: "UNC3886 is a highly adept Chinese cyber espionage group that has targeted and exploited zero-day vulnerabilities in firewall and virtualization technologies, which do not support EDR solutions. UNC3886 has primarily targeted defense, technology, and telecommunication organizations located in the US and APJ regions." Attribution chain: (1) Mandiant canonical UNC3886 designation late 2022: per Mandiant: "In late 2022, Mandiant published details surrounding a novel malware system deployed by UNC3886, a Chinese cyber espionage group, which impacted VMware ESXi hosts, vCenter servers, and Windows virtual machines." (2) VMware ESXi zero-day CVE-2023-20867 June 2023 disclosure: per TechTarget + Mandiant: "the flaw is being used by a Chinese advanced persistent threat group that Mandiant refers to as UNC3886.

VMware said in its security advisory that the flaw, tracked as CVE-2023-20867, is an authentication bypass that can be exploited when a 'fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.'" (3) FortiOS path traversal CVE-2022-41328 March 2023 exploitation: per Mandiant Stealth Mode blog: "UNC3886 took advantage of path traversal vulnerability CVE-2022-41328 to overwrite legitimate files in a normally restricted system directory. With access to targeted organizations' Fortinet devices, the threat actor interacted with VMware vCenter servers." (4) vCenter Server CVE-2023-34048 zero-day exploitation: per Mandiant ongoing tracking: UNC3886 exploited vCenter Server CVE-2023-34048 (out-of-bounds write vulnerability) leveraging access to compromised ESXi hosts. (5) EDR-evasion via edge-platform-non-EDR targeting strategy signature: per Mandiant: "The actor has previously targeted victims via zero-day flaws in firewall and virtualization products, and... continues to target devices and platforms that traditionally lack EDR endpoint detection and response solutions and make use of zero-day exploits on those platforms.

" (6) Custom malware ecosystem canonical Mandiant tracking: per Mandiant
  • VIRTUALPITA + VIRTUALPIE (VMware ESXi backdoors)
  • THINCRUST + CASTLETAP (Fortinet/FortiGate appliance backdoors)
  • TABLEFLIP + REPTILE (FortiGate)
  • DRIEDMOAT (additional backdoor with embedded certificate stolen from compromised appliance)
  • CASTLETAP adapted from REPTILE designed for FortiGate appliances with magic-packet activation.
  • Modified REPTILE source code similar to FOXTROT (7) UNC3886-UNC5325 moderate-confidence association: per Mandiant Feb 2024: "Mandiant identified TTPs and malware code overlaps in LITTLELAMB.WOOLTEA and PITHOOK with malware leveraged by UNC3886. Mandiant assesses with moderate confidence that UNC5325 is associated with UNC3886." (8) UNC3886-UNC5221 (Silk Typhoon) TTP overlap signature: per Mandiant: "UNC3886 shares similar Tactics, Techniques and Procedures (TTPs) with UNC5221, a third group initially identified by Mandiant as exploiting Ivanti zero-days." (9) Anti-forensic indicator-replacement tradecraft canonical signature: per Mandiant VMware ESXi blog: "While past Mandiant blog posts related to UNC3886 have shared atomic indicators like file names and hashes, this particular attacker has been observed replacing indicators mentioned in publications in under a week after their release." Cluster-defining under-one-week-indicator-replacement signature. (10) vpxuser service account credential harvesting via vPostgreSQL database: per Mandiant: "Harvesting credentials for service accounts from a vCenter Server for all connected ESXi hosts from the embedded vPostgreSQL server built into vCenter Server Appliance.
" Operational target profile
  • Defense industrial base primary per Mandiant.
  • Technology organizations signature per Mandiant.
  • Telecommunication organizations signature per Mandiant.
  • US + APJ (Asia-Pacific-Japan) regions signature.
  • VMware ESXi host operators signature.
  • vCenter Server operators signature.
  • FortiGate firewall operators signature.
  • Edge platforms without EDR coverage signature The cluster fills the Mandiant-UNC3886-Chinese- state-sponsored + VMware-ESXi-vCenter-zero-day- specialist + FortiOS-FortiGate-firewall-zero-day- specialist + CVE-2023-20867-VMware-ESXi-auth- bypass + CVE-2022-41328-FortiOS-path-traversal + CVE-2023-34048-vCenter-Server + VIRTUALPITA- VIRTUALPIE-THINCRUST-CASTLETAP-TABLEFLIP-REPTILE- DRIEDMOAT-custom-malware-ecosystem + defense- industrial-base-technology-telecommunication- multi-sector + US-APJ-geographic-distribution + EDR-evasion-edge-platform-non-EDR-targeting + indicator-replacement-under-one-week-anti- forensic + UNC3886-UNC5325-moderate-confidence- association + UNC3886-UNC5221-Silk-Typhoon-TTP- overlap + vpxuser-credential-harvesting-vPostgreSQL position in Mandiant UNC Chinese-state-sponsored network-edge-appliance zero-day specialist cluster cell.
Motivations
china_state_sponsored_cyber_espionage_intelligence_collection, vmware_esxi_vcenter_virtualization_platform_zero_day_specialization, fortios_fortigate_firewall_appliance_zero_day_specialization, edr_evasion_via_edge_platform_non_edr_targeting_strategy, defense_industrial_base_technology_telecommunication_us_apj_targeting, extensive_custom_malware_ecosystem_signature
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)30/60 · 50%
Runtime / container (Falco)8/60 · 13%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)17/60 · 28%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
STOLEN CERTIFICATE EMBEDDED IN BACKDOOR C2 ENCRYPTION SIGNATURE

CVEs Exploited

3
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin