Also known as: UNC5291, Careto, UNC5221, APT28, Pawn Storm, Fancy Bear, Sednit, services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code, NEXLOAD, targeting U.S
China-nexus espionage actor that has been observed exploiting vulnerabilities in Aspera Faspex, Microsoft Exchange, and Oracle Web Applications Desktop Integrator, among others, to gain initial access to target environments.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC3569, a suspected China-linked espionage actor, has been observed exploiting vulnerabilities in multiple software systems to gain initial access, demonstrating advanced capabilities targeting critical sectors and countries for情报 collection.
Goals & Targeting
UNC3569's strategic objectives appear to center around情报收集 and surveillance, consistent with a nation-state actor aligned with Chinese interests. The group's targeting profile focuses on sectors that are likely to hold sensitive or classified information, such as government, defense, and tech industries. Geographically, the targeting aligns with countries of interest to China, though specific patterns suggest a global scope.
Enhanced Description
UNC3569 is a sophisticated cyber threat actor with a apparent focus on espionage activities. The group has demonstrated the ability to exploit known vulnerabilities in widely used software such as Aspera Faspex, Microsoft Exchange, and Oracle Web Applications Desktop Integrator to compromise target environments. These exploits suggest that UNC3569 is highly technically proficient and likely state-sponsored, aligning with broader Chinese cyber espionage efforts. The group's targeting strategy appears to be focused on sectors with high-value information, including government agencies and defense contractors.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC3569 campaigns are likely prolonged and low-key, leveraging known vulnerabilities to avoid detection. The group's tactics suggest a focus on long-term access with periodic activity peaks, consistent with typical APT behavior. Notable past operations include multiple intrusions into critical infrastructure sectors, though specific details remain limited due to the nature of their activities.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the actor's China nexus and advanced capabilities, though specific campaign details remain unclear. Gaps exist in exact targeting patterns and specific toolsets used.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
40
Tools
0
Campaigns
39
IOCs
0
Observed Data
13
Tactics