Threat group.View on attack.mitre.org
UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan (APJ) regions. UNC3886 has displayed a deep understanding of edge devices and virtualization technologies through the exploitation of zero-day vulnerabilities and the use of novel malware families and utilities.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
UNC3886 has used MiniDump to dump process memory and search for cleartext credentials. |
| T1008 Fallback Channels |
UNC3886 has employed layers of redundancy to maintain access to compromised environments including network devices, hypervisors, and virtual machines. |
| T1014 Rootkit |
UNC3886 has used the publicly available rootkits REPTILE and MEDUSA on targeted VMs. |
| T1021.004 SSH |
UNC3886 has established remote SSH access to targeted ESXi hosts. |
| T1027.005 Indicator Removal from Tools |
UNC3886 has replaced atomic indicators mentioned in threat intelligence publications, sometimes as quickly as under a week after release. |
| T1036.004 Masquerade Task or Service |
UNC3886 has named a file ‘fgfm’ in an attempt to disguise it as the legitimate service ‘fgfmd’ which facilitates communication between FortiManager and the FortiGate firewall. |
| T1037 Boot or Logon Initialization Scripts |
UNC3886 has attempted to bypass digital signature verification checks at startup by adding a command to the startup config `/etc/init.d/localnet` within the rootfs.gz archive of both FortiManager and FortiAnalyzer devices. |
| T1037.004 RC Scripts |
UNC3886 has placed a bash installation script into `/etc/rc.local.d/` to establish persistence. |
| T1040 Network Sniffing |
UNC3886 has used the LOOKOVER sniffer to sniff TACACS+ authentication packets. |
| T1057 Process Discovery |
UNC3886 has run scripts to list all running processes on a guest VM from an ESXi host. |
| T1059.001 PowerShell |
UNC3886 has used a PowerShell script to search memory dumps for credentials. |
| T1059.003 Windows Command Shell |
UNC3886 has executed Windows commands on guest virtual machines through `vmtoolsd.exe`. |
| T1059.004 Unix Shell |
UNC3886 has used a bash script to install malicious vSphere Installation Bundles (VIBs). |
| T1059.006 Python |
UNC3886 has used Python scripts to enumerate ESXi hosts and guest VMs. |
| T1059.012 Hypervisor CLI |
UNC3886 has used the esxcli command line utility to modify firewall rules, install malware, and for artifact removal. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.