Also known as: tracked as, GRIDTIDE, associated GitHub Actions, Che, GRIMBOLT, DARK CASTLE, UNC6780, UAC-0050
UNC2814 is a suspected PRC-nexus cyber espionage group that has targeted telecommunications providers and government entities globally since at least 2017. The group employs the GRIDTIDE backdoor to blend malicious traffic with legitimate cloud API activity and utilizes living-off-the-land techniques, including SSH lateral movement and the creation of malicious systemd services. GTIG has confirmed 53 intrusions across 42 countries and identified suspected activity in at least 20 additional nations, with a focus on exfiltrating sensitive communications data. Google has taken significant disruption actions against UNC2814, including infrastructure takedowns and the release of IOCs to aid in detection.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC2814 is a suspected PRC-nexus cyber espionage group targeting telecommunications and government entities globally since at least 2017. The group has been linked to advanced persistent threat (APT) tactics, including the use ofGRIDTIDE backdoor and living-off-the-land techniques such as SSH lateral movement and malicious systemd services. Their primary objective appears to be the exfiltration of sensitive communications data, with confirmed intrusions in 42 countries and suspected activity in at least 20 additional nations.
Goals & Targeting
UNC2814's strategic objectives appear centered around intelligence gathering and espionage, particularly targeting sensitive communications data from telecommunications providers and government entities. Their global reach suggests a focus on broader geopolitical interests, with activity concentrated in regions where such data could provide significant strategic advantage. The group's victims are typically organizations that handle classified or sensitive information, making them high-value targets for exfiltration operations.
Enhanced Description
UNC2814 is a sophisticated cyber espionage group believed to have ties to China, with operations spanning multiple continents. The group has demonstrated a focus on compromising telecommunications providers and government entities, likely seeking sensitive information related to national security and communications infrastructure. Their attack methods include the use of custom malware such as GRIDTIDE, which enables them to blend malicious traffic with legitimate cloud API activity, making detection challenging. Additionally, UNC2814 employs living-off-the-land techniques, leveraging SSH for lateral movement and creating malicious systemd services to maintain persistence on compromised systems. Google has reported significant disruption efforts against this group, including infrastructure takedowns and the release of IOCs to aid in detection.
Software / Tooling
Campaigns & Victims
UNC2814 has been involved in numerous campaigns targeting telecommunications and government sectors globally. Their operational tempo suggests a persistent and methodical approach, with significant effort invested in maintaining long-term access to victim networks. Notable operations include large-scale data exfiltration incidents across multiple countries, with confirmed activity in at least 42 nations and suspected in over 20 more. Google's disruption efforts indicate a significant response to UNC2814's activities, including infrastructure takedowns and IOC releases.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence exists in the group's cyber espionage nature, targeting sectors, and use of GRIDTIDE backdoor. However, specific MITRE ATT&CK mappings and exact campaign details remain uncertain due to limited linked intelligence.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
41
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics