Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC5266

Also known as: TAG-100, Storm-2077, UNC5291, UNC5221, APT28, Pawn Storm, Fancy Bear, Sednit, overlapping with Storm-2077, targeting U.S

Description

Mandiant created UNC5266 to track post-disclosure exploitation leading to deployment of Bishop Fox's SLIVER implant framework, a WARPWIRE variant, and a new malware family that Mandiant has named TERRIBLETEA. At this time, based on observed infrastructure usage similarities, Mandiant suspects with moderate confidence that UNC5266 overlaps in part with UNC3569, a China-nexus espionage actor that has been observed exploiting vulnerabilities in Aspera Faspex, Microsoft Exchange, and Oracle Web Applications Desktop Integrator, among others, to gain initial access to target environments.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Aerospace
Energy
Education
Legal services
Transportation
Manufacturing
Media
Healthcare
Nuclear
Telecommunications
Utilities
Critical infrastructure
Gaming
Non profit

Targeted Countries / Regions

US
CN
TW
KR
GB
JP
KP

AI Analysis

· 2 weeks ago

Executive Summary

UNC5266 is suspected to be an advanced persistent threat (APT) group linked to Chinese state-sponsored espionage activity. The group has demonstrated the ability to exploit known vulnerabilities in enterprise software, deploy custom malware frameworks, and maintain long-term access within compromised networks.

Goals & Targeting

UNC5266 likely has espionage objectives, aiming to gain unauthorized access to sensitive data from targeted sectors such as technology, defense, or government. The group’s focus on exploiting vulnerabilities in widely used enterprise software suggests an effort to compromise high-value targets regardless of geography, though its exact targeting criteria remain under investigation.

Enhanced Description

Mandiant tracks UNC5266 as a potential APT group leveraging post-exploitation tools such as SLIVER implant (Bishop Fox variant), WARPWIRE, and TERRIBLETEA. This group shares infrastructure similarities with UNC3569, another known China-nexus espionage actor who has exploited vulnerabilities in Aspera Faspex, Microsoft Exchange, and Oracle Web Applications Desktop Integrator. The targeting of these enterprise platforms suggests a focus on gaining access to sensitive corporate or government information. UNC5266's operational style indicates a high level of sophistication with TTPs including phishing campaigns and malware development.

Key Capabilities

  • Exploits known vulnerabilities in enterprise software
  • Deploying custom malware frameworks (SLIVER, WARPWIRE, TERRIBLETEA)
  • Spear phishing campaigns
  • Lateral movement within networks
  • Establishing persistence

MITRE ATT&CK Tactics

Exploitation
Lateral Movement
Defense Evasion
Exfiltration

ATT&CK Techniques

T1055
T1486
T1566.002

Software / Tooling

SLIVER Implant
WARPWIRE Variant
TERRIBLETEA Malware
Aspera Faspex Exploit
Microsoft Exchange Exploit

Campaigns & Victims

UNC5266 has been observed deploying custom malware frameworks and exploiting known vulnerabilities to gain initial access. The group likely maintains long-term access once inside a network, aligning with the espionage tradecraft of UNC3569.

IOC Patterns

  • Spear phishing emails with malicious attachments or links
  • Network traffic to domains associated with known TTPs

Recommended Actions

  • Patch all enterprise software regularly
  • Monitor network traffic for indicators of compromise
  • Implement multi-layered cybersecurity solutions
  • Conduct regular user training on phishing simulations

Suggested Tags

APT
espionage
enterprise-targeting
malware
China-nexus

Confidence Assessment

Moderately confident based on Mandiant's analysis and similarities with UNC3569. However, exact targeting criteria and operational timeline remain under investigation.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 7 Domain 6 URL 1 Filename 1 MD5 Hash 5

References

  1. www.recordedfuture.com — Cited by web research for: overlapping with Storm-2077
  2. cloud.google.com — Cited by web research for: targeting U.S
  3. docs.cloud.google.com — Cited by web research for: T1113

Intel Summary

27

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

10

Tactics

Tags

APT
Backdoor / C2
espionage
enterprise-targeting
malware
China-nexus

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.