Also known as: CVE-2026-22769, GRIMBOLT, tracked as, STATIC TUNDRA, also tracked as Sandwo, CovertNetwork-1658, the 7777 Botnet, CVE-2024-39717, technology, manufacturing entities, Sandworm Team, UAC-0050
UNC6201 demonstrates advanced capabilities typical of a state-sponsored APT, combining zero‑day exploitation, sophisticated persistence mechanisms, and lateral movement within virtual infrastructures. The group’s primary campaign began in mid‑2024 when it discovered CVE-2026‑22769 in Dell RecoverPoint appliances, exploiting the vulnerability from edge devices such as VPN concentrators and remote management interfaces to bypass conventional security controls. After establishing footholds, UNC6201 installed Go, Rust, or AOT‑compiled .NET backdoors—most recently GRIMBOLT—to maintain a resilient presence while systematically replacing legacy malware like BRICKSTORM. Operationally the actor operates at the virtualization layer, using custom web shells (SLAYSTYLE) deployed as malicious WAR files via Apache Tomcat Manager’s default admin credentials. This combination of privileged initial access and stealthy persistence allows UNC6201 to exfiltrate sensitive data over encrypted C2 channels (DNS/TCP/HTTP). The group's tooling repertoire includes custom backdoors, open-source utilities, and popular commercial malware families such as LockBit, Conti, and SolarWinds, indicating a hybrid approach that merges bespoke development with repurposed third‑party tools. Strategically, UNC6201 seeks to compromise high-value assets across geopolitical divides, pursuing an intelligence‑collection agenda while maintaining operational deniability through sophisticated evasion tactics. The actor’s focus on virtualization environments highlights an intent to target modern data centers and cloud‑integrated infrastructures, positioning itself to exploit segmentation gaps inherent in hypervisor‑based architectures.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC6201 is a sophisticated Chinese state-sponsored threat actor that has leveraged the zero‑day CVE-2026‑22769 in Dell RecoverPoint for Virtual Machines to gain initial access, establish persistence through backdoors such as GRIMBOLT, and move laterally within virtualized environments. The group targets a broad spectrum of sectors—including government, energy, finance, healthcare, and critical infrastructure—across more than 30 countries. Attack campaigns feature rapid deployment of web shells (SLAYSTYLE) via compromised Apache Tomcat Manager interfaces and ongoing exploitation of the virtualization layer to evade detection.
Goals & Targeting
UNC6201 operates with a clear espionage mandate, targeting government agencies, critical infrastructure, and strategic industries across Asia-Pacific, Europe, North America, and the Middle East. By exploiting virtualization layers and zero‑day vulnerabilities, it seeks unobtrusive long‑term access to facilitate large‑scale data exfiltration while keeping operations below the radar of traditional perimeter defenses.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC6201’s campaigns, active since mid‑2024, have shown a pattern of exploiting high‑impact zero‑days in critical infrastructure software to secure persistent footholds. The actor rapidly migrates from legacy tools (e.g., BRICKSTORM) to newer backdoors (GRIMBOLT), indicating an adaptive operational tempo. Victims span a diverse set of sectors—including energy, defense, finance, and healthcare—across more than 30 countries, demonstrating a global reach and an emphasis on collecting strategic intelligence.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data provides a moderate level of confidence that UNC6201 is exploiting the Dell RecoverPoint zero‑day (CVE-2026-22769) and deploying backdoors such as GRIMBOLT, based on multiple independent reports. However, gaps remain regarding precise attribution links, chronological evidence for the transition from BRICKSTORM to GRIMBOLT, and comprehensive coverage of all affected systems. Continuous monitoring and additional intelligence collection are recommended.
No campaigns linked yet.
No observed data linked yet.
45
Techniques
45
Tools
0
Campaigns
40
IOCs
0
Observed Data
15
Tactics