Also known as: TAG-100, Storm-2077, UNC5291, UNC5221, APT28, Pawn Storm, Fancy Bear, Sednit, overlapping with Storm-2077, targeting U.S
Mandiant created UNC5266 to track post-disclosure exploitation leading to deployment of Bishop Fox's SLIVER implant framework, a WARPWIRE variant, and a new malware family that Mandiant has named TERRIBLETEA. At this time, based on observed infrastructure usage similarities, Mandiant suspects with moderate confidence that UNC5266 overlaps in part with UNC3569, a China-nexus espionage actor that has been observed exploiting vulnerabilities in Aspera Faspex, Microsoft Exchange, and Oracle Web Applications Desktop Integrator, among others, to gain initial access to target environments.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC5266 is suspected to be an advanced persistent threat (APT) group linked to Chinese state-sponsored espionage activity. The group has demonstrated the ability to exploit known vulnerabilities in enterprise software, deploy custom malware frameworks, and maintain long-term access within compromised networks.
Goals & Targeting
UNC5266 likely has espionage objectives, aiming to gain unauthorized access to sensitive data from targeted sectors such as technology, defense, or government. The group’s focus on exploiting vulnerabilities in widely used enterprise software suggests an effort to compromise high-value targets regardless of geography, though its exact targeting criteria remain under investigation.
Enhanced Description
Mandiant tracks UNC5266 as a potential APT group leveraging post-exploitation tools such as SLIVER implant (Bishop Fox variant), WARPWIRE, and TERRIBLETEA. This group shares infrastructure similarities with UNC3569, another known China-nexus espionage actor who has exploited vulnerabilities in Aspera Faspex, Microsoft Exchange, and Oracle Web Applications Desktop Integrator. The targeting of these enterprise platforms suggests a focus on gaining access to sensitive corporate or government information. UNC5266's operational style indicates a high level of sophistication with TTPs including phishing campaigns and malware development.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC5266 has been observed deploying custom malware frameworks and exploiting known vulnerabilities to gain initial access. The group likely maintains long-term access once inside a network, aligning with the espionage tradecraft of UNC3569.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderately confident based on Mandiant's analysis and similarities with UNC3569. However, exact targeting criteria and operational timeline remain under investigation.
No campaigns linked yet.
No observed data linked yet.
27
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
10
Tactics