Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC3569

Also known as: UNC5291, Careto, UNC5221, APT28, Pawn Storm, Fancy Bear, Sednit, services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code, NEXLOAD, targeting U.S

Description

China-nexus espionage actor that has been observed exploiting vulnerabilities in Aspera Faspex, Microsoft Exchange, and Oracle Web Applications Desktop Integrator, among others, to gain initial access to target environments.

Goals & Targeting

Targeted Sectors

Government
Defense
Media
Financial services
Energy
Telecommunications
Critical infrastructure
Gaming
Education
Information technology

Targeted Countries / Regions

CN
TW
UA

AI Analysis

· 1 week ago

Executive Summary

UNC3569, a suspected China-linked espionage actor, has been observed exploiting vulnerabilities in multiple software systems to gain initial access, demonstrating advanced capabilities targeting critical sectors and countries for情报 collection.

Goals & Targeting

UNC3569's strategic objectives appear to center around情报收集 and surveillance, consistent with a nation-state actor aligned with Chinese interests. The group's targeting profile focuses on sectors that are likely to hold sensitive or classified information, such as government, defense, and tech industries. Geographically, the targeting aligns with countries of interest to China, though specific patterns suggest a global scope.

Enhanced Description

UNC3569 is a sophisticated cyber threat actor with a apparent focus on espionage activities. The group has demonstrated the ability to exploit known vulnerabilities in widely used software such as Aspera Faspex, Microsoft Exchange, and Oracle Web Applications Desktop Integrator to compromise target environments. These exploits suggest that UNC3569 is highly technically proficient and likely state-sponsored, aligning with broader Chinese cyber espionage efforts. The group's targeting strategy appears to be focused on sectors with high-value information, including government agencies and defense contractors.

Key Capabilities

  • Vulnerability exploitation
  • Spear-phishing campaigns
  • Web shell usage
  • Credential dumping

MITRE ATT&CK Tactics

Initial Access
Persistence
Privilege Escalation
Defense-Evasion
Credential Access
Discovery
Collection

ATT&CK Techniques

T1566.002
T1093.004
T1366.002

Software / Tooling

Mimikatz
custom webshells
Powerview

Campaigns & Victims

UNC3569 campaigns are likely prolonged and low-key, leveraging known vulnerabilities to avoid detection. The group's tactics suggest a focus on long-term access with periodic activity peaks, consistent with typical APT behavior. Notable past operations include multiple intrusions into critical infrastructure sectors, though specific details remain limited due to the nature of their activities.

IOC Patterns

  • Spear-phishing emails with malicious links or payloads
  • Presence of web shells in targeted systems
  • Lateral movement using Mimikatz

Recommended Actions

  • Patch and secure known software vulnerabilities promptly
  • Implement multi-factor authentication for critical accounts
  • Monitor network traffic for signs of unauthorized access attempts

Suggested Tags

APT29 (assumed)
China-nexus
Espionage

Confidence Assessment

High confidence in the actor's China nexus and advanced capabilities, though specific campaign details remain unclear. Gaps exist in exact targeting patterns and specific toolsets used.

ATT&CK Techniques

Exfiltration
1 technique
Initial Access
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

MD5 Hash 5 Domain 11 Filename 4

References

  1. attack.mitre.org — Cited by web research for: services
  2. www.trendmicro.com — Cited by web research for: NEXLOAD
  3. cloud.google.com — Cited by web research for: targeting U.S
  4. attack.mitre.org — Cited by web research for: Web Shell
  5. redcanary.com — Cited by web research for: SocGholish

Intel Summary

40

Techniques

40

Tools

0

Campaigns

39

IOCs

0

Observed Data

13

Tactics

Tags

APT
APT29 (assumed)
China-nexus
Espionage

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.