Also known as: LuckyMouse, tracked as, 2026, EmissaryPanda, UNC5174 by Mandiant, GOREVERSE, Mysterious Elephant, NosyDoor, CVE-2025-21590
China‑Nexus operates as a modular threat actor capable of executing automated, spray‑and‑scan campaigns across more than 100 countries. Its arsenal includes zero‑day CVEs in Fortinet firewalls (CVE‑2025‑21590), VMware hypervisors, and Ivanti Endpoint Manager (CVE‑2025‑4428, CVE‑2024‑8963/8190). Once initial access is achieved, the group leverages a sophisticated loader ecosystem that can deliver PlugX or Cobalt Strike derivatives over HTTPS, WebSocket, TCP, UDP or DNS‑over‑HTTPS. A hallmark of China‑Nexus operations is their dual focus on network infrastructure. Custom backdoors (TINYSHELL) are implanted on Juniper MX routers and Solaris‑based Junos OS devices, bypassing veriexec through CVE‑2025‑21590 and disabling audit logs. The same technique allows for lateral movement to vSphere hosts, where REPTILE/MEDUSA rootkits and modified sshd services provide persistent footholds. On host systems, the attackers rely on a blend of .NET stagers (NetDraft), Go loaders (SNOWLIGHT/SNOWRUST), and compressed, encrypted payloads delivered via LNK or CHM droppers. DLL sideloading, control‑flow flattening, RC4/AES-HMAC encryption and timestomping are used to evade detection and forensic analysis. The backdoors maintain persistence through registry Run keys, Windows services (VGAuthService) and Linux systemd units. China‑Nexus runs its command‑and‑control infrastructure over a multi‑domain, multi–IP network that employs SOCKS5 relays, HTTP/S traffic, DNS‑over‑HTTPS tunnels and custom proxy chains. The use of compromised VPN appliances and cloud services (e.g., Ivanti and Check Point) further expands their reach while complicating attribution. The group’s recent operations emphasize targeting the Arabian Gulf region, with extensive campaigns against telecom providers, defense ministries, and medical research institutions. Long‑term dwell times—often up to five years—underscore a strategic espionage focus on intellectual property and critical national security information.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
China‑Nexus (UNC3886/UNC5174/UAT‑8302) is a sophisticated state-backed espionage group that targets critical infrastructure and high‑value entities worldwide. The actors employ zero‑day exploits, custom backdoors on network devices, and highly obfuscated multi‑stage loaders to gain long‑term access while remaining hidden behind covert proxy networks.
Goals & Targeting
China‑Nexus seeks to acquire highly sensitive data such as defense technologies, AI research outputs, financial intelligence, and operational details of telecommunications, transport and critical‑infrastructure sectors. Their tactics indicate an emphasis on covert reconnaissance through compromised vendor infrastructure and lateral movement within target networks, with the ultimate goal of achieving persistent footholds for ongoing spying and IP theft.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
China‑Nexus has conducted at least two large‑scale campaigns spanning 2024–2026, targeting governments, telecom providers and critical infrastructure across the US, APJ and the Arabian Gulf region. The group frequently uses a combination of exploited zero‑days in enterprise software (Fortinet firewalls, VMware ESXi, Ivanti Connect Secure) with malicious backdoors left on routers and hypervisors for long‑term persistence. Operations often involve automated spray‑and‑scan modules that deposit staging servers at 130.94.17.180, dropping Cobalt Strike or PlugX staging loaders over multiple ports and protocols. The actors’ use of multi‑hop proxies (ORB relay) and DNS‑over‑HTTPS tunnels complicates attribution and detection, enabling them to maintain covert footholds for years while exfiltrating data through encrypted channels. Notable past operations include the September 2024 attack on a Qatar telecom with a TINYSHELL implant on Juniper routers, the March 2025 compromise of a U.S. medical research facility via an exposed web server hosting a DLL dropper, and the July 2026 breach of several Saudi government ministries using PlugX delivered through a malicious CHM file that leveraged DLL sideloading and timestomping. The group’s persistence tactics—rootkits on ESXi guests, systemd units on Linux hosts, registry Run keys, and Windows services named VGAuthService—combined with long‑term data staging in memory or encrypted archives highlight their focus on stealthy, sustained espionage rather than destructive sabotage.
IOC Patterns
Recommended Actions
No campaigns linked yet.
No observed data linked yet.
40
Techniques
50
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics