Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC2814

Also known as: tracked as, GRIDTIDE, associated GitHub Actions, Che, GRIMBOLT, DARK CASTLE, UNC6780, UAC-0050

Description

UNC2814 is a suspected PRC-nexus cyber espionage group that has targeted telecommunications providers and government entities globally since at least 2017. The group employs the GRIDTIDE backdoor to blend malicious traffic with legitimate cloud API activity and utilizes living-off-the-land techniques, including SSH lateral movement and the creation of malicious systemd services. GTIG has confirmed 53 intrusions across 42 countries and identified suspected activity in at least 20 additional nations, with a focus on exfiltrating sensitive communications data. Google has taken significant disruption actions against UNC2814, including infrastructure takedowns and the release of IOCs to aid in detection.

Goals & Targeting

Targeted Sectors

Telecommunications
Government
Financial services
Defense
Media
Critical infrastructure
Manufacturing
Non profit
Aerospace
Transportation
Energy
Utilities

Targeted Countries / Regions

CN
RU
UA
FR
US
DE
RO
NL
KP

AI Analysis

· 1 week ago

Executive Summary

UNC2814 is a suspected PRC-nexus cyber espionage group targeting telecommunications and government entities globally since at least 2017. The group has been linked to advanced persistent threat (APT) tactics, including the use ofGRIDTIDE backdoor and living-off-the-land techniques such as SSH lateral movement and malicious systemd services. Their primary objective appears to be the exfiltration of sensitive communications data, with confirmed intrusions in 42 countries and suspected activity in at least 20 additional nations.

Goals & Targeting

UNC2814's strategic objectives appear centered around intelligence gathering and espionage, particularly targeting sensitive communications data from telecommunications providers and government entities. Their global reach suggests a focus on broader geopolitical interests, with activity concentrated in regions where such data could provide significant strategic advantage. The group's victims are typically organizations that handle classified or sensitive information, making them high-value targets for exfiltration operations.

Enhanced Description

UNC2814 is a sophisticated cyber espionage group believed to have ties to China, with operations spanning multiple continents. The group has demonstrated a focus on compromising telecommunications providers and government entities, likely seeking sensitive information related to national security and communications infrastructure. Their attack methods include the use of custom malware such as GRIDTIDE, which enables them to blend malicious traffic with legitimate cloud API activity, making detection challenging. Additionally, UNC2814 employs living-off-the-land techniques, leveraging SSH for lateral movement and creating malicious systemd services to maintain persistence on compromised systems. Google has reported significant disruption efforts against this group, including infrastructure takedowns and the release of IOCs to aid in detection.

Software / Tooling

GRIDTIDE backdoor
Custom PowerShell scripts for malicious activities
Living-off-the-land tools

Campaigns & Victims

UNC2814 has been involved in numerous campaigns targeting telecommunications and government sectors globally. Their operational tempo suggests a persistent and methodical approach, with significant effort invested in maintaining long-term access to victim networks. Notable operations include large-scale data exfiltration incidents across multiple countries, with confirmed activity in at least 42 nations and suspected in over 20 more. Google's disruption efforts indicate a significant response to UNC2814's activities, including infrastructure takedowns and IOC releases.

IOC Patterns

  • Spear-phishing emails with malicious cloud API requests
  • Unusual SSH authentication attempts
  • Malicious systemd service creation
  • Abnormal API traffic patterns

Recommended Actions

  • Enhance monitoring of cloud API traffic for suspicious patterns
  • Implement strict access controls on SSH services and log unusual activities
  • Deploy endpoint detection and response (EDR) solutions to detect living-off-the-land behaviors
  • Conduct regular network vulnerability assessments focusing on potential APT indicators
  • Engage in active threat hunting exercises targeting known UNC2814 TTPs
  • Enforce multi-factor authentication (MFA) for sensitive systems and accounts

Suggested Tags

APT
espionage
cyber-espionage
telecommunications
government

Confidence Assessment

High confidence exists in the group's cyber espionage nature, targeting sectors, and use of GRIDTIDE backdoor. However, specific MITRE ATT&CK mappings and exact campaign details remain uncertain due to limited linked intelligence.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 17 SHA-256 Hash 2 Domain 1

References

  1. cloud.google.com — Cited by web research for: GRIDTIDE
  2. cloud.google.com — Cited by web research for: associated GitHub Actions
  3. cert.europa.eu — Cited by web research for: GRIMBOLT
  4. attack.mitre.org — Cited by web research for: T1595
  5. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl
  6. www.ampcuscyber.com — Cited by web research for: CALENDAR
  7. www.techradar.com — Cited by web research for: WhatsApp

Intel Summary

40

Techniques

41

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

APT
Backdoor / C2
Government Targeting
espionage
cyber-espionage
telecommunications
government

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.