Home/Threat Actor/UNC4191
Threat Actor

UNC4191

unc4191 · china · active since 2022-09

UNC4191 (Mandiant canonical designation, November 28, 2022 first-disclosure) is a China-aligned cyber espionage cluster targeting Philippine government, energy, and military organizations and adjacent Southeast Asian organizations via USB-borne malware propagation.

operationally distinctive in China-aligned cluster ecosystem for USB-mediated propagation tradecraft enabling targeting of air-gapped or limited- internet-connectivity victim environments including military networks and government classified networks.

targeting concentration on Philippines consistent with Chinese state intelligence priorities during 2022-2024 South China Sea tensions (territorial disputes around Scarborough Shoal and Spratly Islands, expanded US-Philippines defense cooperation under EDCA, 2023 expansion of US military access to Philippine bases)

custom tooling includes MISTCLOAK loader, DARKDEW backdoor, BLUEHAZE downloader.

USB-borne propagation via shortcut/LNK-file lures and autorun.inf abuse.

USB- mediated lateral movement and exfiltration capability for air-gapped target data extraction.

operationally distinct from but ecosystem-adjacent to all other Chinese-aligned clusters curated separately in this corpus.

china confidence: high 7 aliases

Profile

UNC4191 (Mandiant canonical designation, November 28, 2022 first-disclosure) is a China-aligned cyber espionage cluster canonically disclosed by Mandiant as a China-nexus operational cluster targeting Philippine government, energy, and military organizations and adjacent Southeast Asian organizations via USB-borne malware propagation. The cluster's operational distinctiveness in the China-aligned cluster ecosystem is the USB-mediated propagation tradecraft, operationally distinct from China-aligned clusters which more commonly rely on spearphishing, perimeter-appliance exploitation, or drive-by web compromise for initial access. The USB-mediated propagation pattern is operationally significant for targeting air-gapped or limited-internet- connectivity victim environments, including military networks, government classified networks, and selectively other high-security victim environments where conventional internet-based initial access vectors are not viable.

The operational pattern is operationally similar to legacy USB-worm patterns (Stuxnet, USB-spreading worm families) but operationally applied by a state-aligned espionage cluster rather than for opportunistic mass propagation or destructive operations. The cluster's targeting concentration on Philippine governmental, energy, and military organizations is operationally consistent with documented Chinese state intelligence priorities during the 2022-2024 period of heightened tensions in the South China Sea, including Philippine-China territorial disputes around Scarborough Shoal and the Spratly Islands, expanded US-Philippines defense cooperation under the Enhanced Defense Cooperation Agreement (EDCA), and 2023 expansion of US military access to Philippine bases. The strategic-context alignment operationally supports the Mandiant attribution assessment of UNC4191 as China-nexus.

Operational tradecraft includes USB-borne malware propagation via shortcut/LNK-file lures and autorun.inf abuse, custom malware deployment (MISTCLOAK custom loader, DARKDEW custom backdoor, BLUEHAZE custom downloader), DLL side-loading delivery chains, USB-mediated lateral movement within victim networks, and USB-mediated exfiltration capability for air-gapped target data extraction. Commodity tools (mimikatz, fscan Chinese-language network scanner, frp reverse proxy) supplement the cluster's signature USB-borne tooling. UNC4191 is operationally distinct from all other Chinese- aligned clusters curated separately in this corpus and fills the USB-mediated-propagation / air-gapped-target- capable cell in the curated Chinese-cluster coverage.

Aliases

7
unc4191unc 4191uncategorized-4191china-aligned-usb-clusterphilippines-southeast-asia-usb-targeting-clusterusb-borne-malware-china-aligned-2022unc_4191

Notable Campaigns

3
2022-2024USB-Borne Malware Propagation Operational Signature
2022-2024Philippines Targeting Strategic Context, South China Sea Disputes
2022Mandiant Canonical Public Disclosure, UNC4191 (November 2022)

Attribution & Reporting

Attributed by
Mandiant (Google Threat Intelligence)Microsoft Threat IntelligenceCrowdStrikeTrend MicroRecorded FutureSymantec / Broadcom Threat Hunter TeamSentinelOnePhilippine National Bureau of Investigation
Key reporting
reportMandiant: Always Another Secret, Lifting the Haze on China-Nexus Espionage in Southeast Asia (November 28, 2022), canonical first-disclosure
reportGoogle Threat Intelligence: UNC4191 China-Nexus Philippines Analysis
reportMicrosoft Threat Intelligence: China-Aligned Southeast Asia Espionage Coverage
reportMalpedia Actor Profile: UNC4191

Operational

State sponsor

China-aligned cyber espionage cluster canonically disclosed by Mandiant (now Google Threat Intelligence) in November 2022 as a China-nexus operational cluster targeting Philippine government, energy, and military organizations and adjacent Southeast Asian organizations via USB-borne malware propagation. Mandiant's attribution is based on operational tradecraft consistent with Chinese state-aligned cyber espionage operations (custom malware development, sustained targeting of Southeast Asian strategic-interest victims, operational tradecraft consistent with PRC intelligence priorities), targeting profile (Philippine government and military organizations during a period of heightened US-Philippines defense cooperation and Philippine- China territorial disputes in the South China Sea, consistent with Chinese state intelligence priorities for Philippine governmental and military intelligence collection), tooling lineage (custom malware including MISTCLOAK and DARKDEW with code patterns consistent with broader Chinese- aligned cluster tooling ecosystem), and infrastructure analysis. The cluster has not been formally attributed by any government cybersecurity authority to a specific Chinese government agency, military unit (PLA SSF), or intelligence service (MSS).

The cluster's signature operational tradecraft is USB-borne malware propagation, operationally distinctive among China-aligned clusters which more commonly rely on spearphishing or perimeter-appliance exploitation for initial access. The cluster is operationally distinct from the broader Chinese-aligned cluster ecosystem curated in this corpus including Volt Typhoon (volt_typhoon.yaml), Salt Typhoon (salt_typhoon.yaml), Silk Typhoon (silk_typhoon.yaml), Flax Typhoon (flax_typhoon.yaml), Storm-0558 (storm_0558.yaml), Earth Estries (earth_estries.yaml), TAG-100 (tag_100.yaml), Velvet Ant (velvet_ant.yaml), GhostEmperor (ghostemperor.yaml), ToddyCat (toddycat.yaml), Earth Lusca (earth_lusca.yaml), and the APT* China-aligned clusters.

Motivations
cyber_espionage, philippines_government_intelligence_collection, southeast_asian_intelligence_collection, chinese_state_intelligence_priorities, south_china_sea_dispute_related_intelligence, air_gapped_network_targeting_via_usb
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)55/60 · 91%
Analytics (MITRE CAR)34/60 · 56%
Runtime / container (Falco)9/60 · 15%
File / malware (YARA)1/60 · 1%
Network (Suricata/Snort)15/60 · 25%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MISTCLOAKSHORTCUT LNK LURE COMPONENTS
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin