Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC6201

Also known as: CVE-2026-22769, GRIMBOLT, tracked as, STATIC TUNDRA, also tracked as Sandwo, CovertNetwork-1658, the 7777 Botnet, CVE-2024-39717, technology, manufacturing entities, Sandworm Team, UAC-0050

Description

UNC6201 demonstrates advanced capabilities typical of a state-sponsored APT, combining zero‑day exploitation, sophisticated persistence mechanisms, and lateral movement within virtual infrastructures. The group’s primary campaign began in mid‑2024 when it discovered CVE-2026‑22769 in Dell RecoverPoint appliances, exploiting the vulnerability from edge devices such as VPN concentrators and remote management interfaces to bypass conventional security controls. After establishing footholds, UNC6201 installed Go, Rust, or AOT‑compiled .NET backdoors—most recently GRIMBOLT—to maintain a resilient presence while systematically replacing legacy malware like BRICKSTORM. Operationally the actor operates at the virtualization layer, using custom web shells (SLAYSTYLE) deployed as malicious WAR files via Apache Tomcat Manager’s default admin credentials. This combination of privileged initial access and stealthy persistence allows UNC6201 to exfiltrate sensitive data over encrypted C2 channels (DNS/TCP/HTTP). The group's tooling repertoire includes custom backdoors, open-source utilities, and popular commercial malware families such as LockBit, Conti, and SolarWinds, indicating a hybrid approach that merges bespoke development with repurposed third‑party tools. Strategically, UNC6201 seeks to compromise high-value assets across geopolitical divides, pursuing an intelligence‑collection agenda while maintaining operational deniability through sophisticated evasion tactics. The actor’s focus on virtualization environments highlights an intent to target modern data centers and cloud‑integrated infrastructures, positioning itself to exploit segmentation gaps inherent in hypervisor‑based architectures.

Goals & Targeting

Targeted Sectors

Government
Financial services
Energy
Defense
Telecommunications
Healthcare
Critical infrastructure
Manufacturing
Transportation
Aviation
Maritime
Media
Education
Information technology
Chemical
Think tank
Aerospace
Construction
Legal services
Oil gas
Hospitality
Non profit
Nuclear

Targeted Countries / Regions

CN
US
UA
RU
IN
JP
DE
FR
AU
KR
GB
PL
CA
SG
VN
TW
IR
KZ
IL
TR
BR
MX
ES
IT
RO
NL
KP

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 7 hours ago

Executive Summary

UNC6201 is a sophisticated Chinese state-sponsored threat actor that has leveraged the zero‑day CVE-2026‑22769 in Dell RecoverPoint for Virtual Machines to gain initial access, establish persistence through backdoors such as GRIMBOLT, and move laterally within virtualized environments. The group targets a broad spectrum of sectors—including government, energy, finance, healthcare, and critical infrastructure—across more than 30 countries. Attack campaigns feature rapid deployment of web shells (SLAYSTYLE) via compromised Apache Tomcat Manager interfaces and ongoing exploitation of the virtualization layer to evade detection.

Goals & Targeting

UNC6201 operates with a clear espionage mandate, targeting government agencies, critical infrastructure, and strategic industries across Asia-Pacific, Europe, North America, and the Middle East. By exploiting virtualization layers and zero‑day vulnerabilities, it seeks unobtrusive long‑term access to facilitate large‑scale data exfiltration while keeping operations below the radar of traditional perimeter defenses.

Enhanced Description

Key Capabilities

  • Command and Control via application‑layer protocols
  • Ingress transfer of malware
  • Exfiltration of data over encrypted C2 channels
  • Execution via cross‑platform backdoor written in Go, Rust or AOT‑compiled .NET
  • Zero‑day exploitation of Dell RecoverPoint for Virtual Machines (CVE-2026-22769) to maintain persistence and facilitate lateral movement
  • Exploitation of Apache Tomcat Manager using default admin account and deployment of malicious WAR files
  • Installation of web shell SLAYSTYLE for remote execution
  • Persistent backdoor GRIMBOLT replacing legacy BRICKSTORM binaries
  • Facilitated lateral movement within virtual environments

MITRE ATT&CK Tactics

Initial Access
Persistence
Execution
Command and Control
Exfiltration
Credential Access
Lateral Movement
Defense Evasion

ATT&CK Techniques

T1190
T1071
T1041
T1003.001
T1068
T1071.001
T1583.007
T1213.002
T1543
T1584.008
T1489
T1572
T1505.003
T1090
T1059
T1083
T1568
T1102
T1098.001
T1067
T1121
T1136
T1550.001

Software / Tooling

BRICKSTORM
SLAYSTYLE
GRIMBOLT

Campaigns & Victims

UNC6201’s campaigns, active since mid‑2024, have shown a pattern of exploiting high‑impact zero‑days in critical infrastructure software to secure persistent footholds. The actor rapidly migrates from legacy tools (e.g., BRICKSTORM) to newer backdoors (GRIMBOLT), indicating an adaptive operational tempo. Victims span a diverse set of sectors—including energy, defense, finance, and healthcare—across more than 30 countries, demonstrating a global reach and an emphasis on collecting strategic intelligence.

IOC Patterns

  • CVE-2026-22769 vulnerability exploitation
  • Malicious WAR files deployed via Apache Tomcat Manager
  • Web shell SLAYSTYLE installation
  • Apache Tomcat Manager default admin credential usage
  • Hash‑SHA256 samples of backdoor binaries
  • Domain patterns related to staging and command‑and‑control

Recommended Actions

  • Patch all Dell RecoverPoint appliances to mitigate CVE-2026-22769 immediately.
  • Restrict access to Apache Tomcat Manager, enforce least privilege and mandatory password rotation, and disable default admin credentials.
  • Disable or harden unused web services on RecoverPoint devices to limit attack surface.
  • Monitor for anomalous outbound DNS, HTTP/HTTPS traffic indicative of backdoor C2 activity.
  • Implement hypervisor‑level monitoring and micro‑segmentation to detect lateral movement within virtual environments.
  • Deploy host‑based intrusion detection systems capable of detecting known backdoors such as GRIMBOLT or SLAYSTYLE.

Suggested Tags

UNC6201
PRC state actor
Dell RecoverPoint CVE-2026-22769
BRICKSTORM
SLAYSTYLE
GRIMBOLT
Chinese APT
Zero‑day exploitation
Virtualization layer threat

Confidence Assessment

The available data provides a moderate level of confidence that UNC6201 is exploiting the Dell RecoverPoint zero‑day (CVE-2026-22769) and deploying backdoors such as GRIMBOLT, based on multiple independent reports. However, gaps remain regarding precise attribution links, chronological evidence for the transition from BRICKSTORM to GRIMBOLT, and comprehensive coverage of all affected systems. Continuous monitoring and additional intelligence collection are recommended.

ATT&CK Techniques

Credential Access
1 technique
Defense impairment
1 technique
Exfiltration
1 technique
Impact
1 technique
Lateral Movement
1 technique
Privilege Escalation
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 19 IPv4 Address 1

References

  1. cloud.google.com — Cited by web research for: GRIMBOLT
  2. attack.mitre.org — Cited by web research for: STATIC TUNDRA
  3. www.crowdstrike.com — Cited by web research for: technology
  4. cloud.google.com — Cited by web research for: T1071.001
  5. attack.mitre.org — Cited by web research for: T1572
  6. cert.europa.eu — Cited by web research for: Qilin
  7. https://attack.mitre.org/software/ — Cited by AI analysis.
  8. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?page=6 — Cited by AI analysis.

Intel Summary

45

Techniques

45

Tools

0

Campaigns

40

IOCs

0

Observed Data

15

Tactics

Tags

APT
Backdoor / C2
cyber espionage
infrastructure-targeting
nation-state
Chinese threat group
UNC6201
PRC state actor
Dell RecoverPoint CVE-2026-22769
BRICKSTORM
SLAYSTYLE
GRIMBOLT
Chinese APT
Zero‑day exploitation
Virtualization layer threat

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.