Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC6691

Also known as: tracked as, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, CryptoWaters, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code

Description

UNC6691 is a financially motivated threat actor operating out of China. Leveraging a wide spectrum of technical capabilities, the group targets organizations in media, finance, defense, government, non‑profit, IT, and retail sectors worldwide. Recent intelligence indicates that UNC6691 frequently exploits public cloud environments for infrastructure acquisition and uses obfuscated scripts or malware to maintain persistence. Operationally, the actor combines social engineering (spear‑phishing), credential dumping, and a suite of remote access tools (RATs) to infiltrate target networks. Once inside, UNC6691 can discover network resources through container/host discovery, mount cloud services or compromise host binaries. The group also conducts automated collection and exfiltration over standard application layer protocols. The attacks often culminate in data theft or financial extortion, with evidence of ransomware‑like behaviors such as account manipulation and removal to prevent detection. UNC6691’s arsenal includes custom scripts written in PowerShell and command‑line interpreters combined with legitimate utilities like netsh.exe and BITS jobs for covert communication. Despite its activity across a wide range of industries, the actor remains relatively low‑profile compared to larger APT groups, likely due to reliance on opportunistic exploitation rather than nation‑state directed campaigns.

Goals & Targeting

Targeted Sectors

Media
Financial services
Defense
Government
Non profit
Information technology
Retail

Targeted Countries / Regions

CN

AI Analysis

Grounded in web research
2026 only
· 4 days ago

Executive Summary

UNC6691 is a financially motivated, China‑based threat actor that utilizes a broad set of tactics to infiltrate and monetize compromised systems. The group employs sophisticated persistence mechanisms, cloud infrastructure exploitation, and stealthy exfiltration techniques across multiple sectors. CISO teams should treat UNC6691 as an ongoing adversary capable of rapid lateral movement and data theft.

Goals & Targeting

UNC6691’s strategic objectives revolve around maximizing financial gain through data theft, extortion, and possibly ransomware. By focusing on media, finance, defense, government, non‑profit, IT, and retail sectors, the group seeks entities that handle valuable personal or corporate data and those with less mature security postures. The prevalent targeting of organizations in China indicates a preference for domestic markets where regulatory oversight may be weaker, while opportunistic attacks on foreign targets exploit globally shared cloud platforms. Typical victims are mid‑to‑large enterprises willing to pay for rapid remediation. Key objectives include establishing persistence via boot or logon scripts, collecting credentials and sensitive data, leveraging cloud infrastructure for staging, and ultimately exfiltrating the stolen assets or using them as leverage in negotiation. The actor also appears interested in creating a wide range of reusable tools (e.g., RATs, exploit kits) to accelerate future attacks.

Enhanced Description

Key Capabilities

  • Boot or logon initialization scripts for persistence
  • Adversary‑in‑the‑middle capabilities with compromised infrastructure
  • Cloud infrastructure acquisition and discovery
  • Automated data collection via PowerShell/scripts
  • Clipboard data exfiltration
  • Audio capture for espionage
  • Browser hijacking (session & cache) Remote file transfer via BITS jobs or rundll32
  • Obfuscated files/commands to evade detection
  • Account discovery, manipulation, elevation controls
  • Use of legitimate Windows utilities (netsh.exe, systemd)
  • Privilege escalation via process hollowing or DLL injection

ATT&CK Techniques

Exfiltration
1 technique
Initial Access
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 19 SHA-256 Hash 1

References

  1. attack.mitre.org — Cited by web research for: services
  2. redcanary.com — Cited by web research for: SocGholish
  3. attack.mitre.org — Cited by web research for: Process Hollowing
  4. cloud.google.com — Cited by web research for: CVE-2024-23222
  5. www.bitdefender.com — Cited by web research for: CVE-2026-20700

Intel Summary

40

Techniques

41

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

Financially motivated
China-based threat actor
APT

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.