UNC3886

G1048

Threat group.View on attack.mitre.org

About this group

UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan (APJ) regions. UNC3886 has displayed a deep understanding of edge devices and virtualization technologies through the exploitation of zero-day vulnerabilities and the use of novel malware families and utilities.

Techniques used49

Procedure examples49

TechniqueProcedure example
T1003.001
LSASS Memory

UNC3886 has used MiniDump to dump process memory and search for cleartext credentials.

T1008
Fallback Channels

UNC3886 has employed layers of redundancy to maintain access to compromised environments including network devices, hypervisors, and virtual machines.

T1014
Rootkit

UNC3886 has used the publicly available rootkits REPTILE and MEDUSA on targeted VMs.

T1021.004
SSH

UNC3886 has established remote SSH access to targeted ESXi hosts.

T1027.005
Indicator Removal from Tools

UNC3886 has replaced atomic indicators mentioned in threat intelligence publications, sometimes as quickly as under a week after release.

T1036.004
Masquerade Task or Service

UNC3886 has named a file ‘fgfm’ in an attempt to disguise it as the legitimate service ‘fgfmd’ which facilitates communication between FortiManager and the FortiGate firewall.

T1037
Boot or Logon Initialization Scripts

UNC3886 has attempted to bypass digital signature verification checks at startup by adding a command to the startup config `/etc/init.d/localnet` within the rootfs.gz archive of both FortiManager and FortiAnalyzer devices.

T1037.004
RC Scripts

UNC3886 has placed a bash installation script into `/etc/rc.local.d/` to establish persistence.

T1040
Network Sniffing

UNC3886 has used the LOOKOVER sniffer to sniff TACACS+ authentication packets.

T1057
Process Discovery

UNC3886 has run scripts to list all running processes on a guest VM from an ESXi host.

T1059.001
PowerShell

UNC3886 has used a PowerShell script to search memory dumps for credentials.

T1059.003
Windows Command Shell

UNC3886 has executed Windows commands on guest virtual machines through `vmtoolsd.exe`.

T1059.004
Unix Shell

UNC3886 has used a bash script to install malicious vSphere Installation Bundles (VIBs).

T1059.006
Python

UNC3886 has used Python scripts to enumerate ESXi hosts and guest VMs.

T1059.012
Hypervisor CLI

UNC3886 has used the esxcli command line utility to modify firewall rules, install malware, and for artifact removal.

View all 49 procedure examples

Software8

Campaigns1

References2

  1. Google Cloud Threat Intelligence VMWare ESXi Zero-Day 2023 Open source
    Alexander Marvi, Brad Slaybaugh, Ron Craft, and Rufus Brown. (2023, June 13). VMware ESXi Zero-Day Used by Chinese Espionage Actor to Perform Privileged Guest Operations on Compromised Hypervisors. Retrieved March 26, 2025.
  2. Mandiant Fortinet Zero Day Open source
    Marvi, A. et al.. (2023, March 16). Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation. Retrieved March 22, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.