Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC3886

Also known as: tracked as, CVE-2025-21590

Description

UNC3886 is a sophisticated China‑linked espionage group that has conducted targeted attacks on high-value infrastructure since at least 2022. The actor demonstrates deep knowledge of edge networking equipment and virtualization technologies, exploiting multiple zero‑day vulnerabilities—most notably CVE‑2023‑34048 in VMware vCenter, CVE‑2025‑21590 in Juniper MX routers, and Fortinet CVEs such as CVE‑2023‑34048—to gain unauthenticated remote command execution and bypass veriexec protections. Once inside the network, UNC3886 deploys a suite of custom backdoors: TinyShell on Juniper devices, REPTILE and MEDUSA rootkits on Windows/Unix guests, and malicious VMware vSphere Installation Bundles (VIBs) that persist through ESXi host reboots. The group also installs backdoored SSH daemons, uses esxcli to modify firewall rules, and removes logs via script manipulation and memory injection into legitimate processes. Data exfiltration is performed in stages—credentials are XOR‑encrypted or stored using RC4, files are compressed with Gzip/makecab, staged locally on the compromised device, then transmitted over custom UDP/TCP sockets (default port 45678) or via hidden libpcap packet‑sniffing modules. The malware consistently obfuscates its traffic and clears shell history (HISTFILE). Overall, UNC3886’s toolkit blends publicly known exploitation mechanisms with bespoke, long‑lived persistence vectors to maintain stealth across virtualized environments.

Goals & Targeting

Targeted Sectors

Telecommunications
Defense
Government
Critical infrastructure
Energy
Utilities
Aviation
Healthcare
Maritime
Aerospace

Targeted Countries / Regions

CN
SG
US
JP
RU
IR
KP

AI Analysis

Grounded in web research
· analyzed in 4 chunks · 2 days ago

Executive Summary

UNC3886 is a China‑nexus cyberespionage actor that has been active since at least 2022, targeting defense, telecom, and critical infrastructure organizations worldwide, including the United States, Japan, Singapore and Russia. The group leverages zero‑day vulnerabilities in VMware vCenter, Fortinet FortiGate, and Juniper MX routers to deploy custom backdoors (TinyShell, REPTILE, MEDUSA) and establish long‑term persistence on edge devices and hypervisors. Its operations combine credential theft, data staging, obfuscated C2 channels, and extensive defense‑evasion techniques to exfiltrate intelligence from privileged IT environments.

Goals & Targeting

UNC3886 conducts espionage aimed at acquiring strategic intelligence from defense, governmental, telecommunications, aviation, aerospace, and critical infrastructure sectors. By targeting edge routers and hypervisors that sit between service providers and enterprise networks, the group gains privileged visibility into vast amounts of operational data. The attacker’s preference for zero‑day vulnerabilities and custom backdoors indicates an objective to remain undetected over long periods while gathering actionable intelligence from highly protected environments.

Enhanced Description

Key Capabilities

  • Zero-day vulnerability exploitation in VMware vCenter, Fortinet FortiGate, Juniper MX routers
  • Deployment of custom TinyShell backdoor on Juniper devices and backdoored SSH clients/daemons
  • Use of rootkits REPTILE and MEDUSA on virtual machines for stealth persistence
  • Persistence via malicious VMware vSphere Installation Bundles (VIBs) and exploitation of ESXi admin commands
  • Defense‑evasion through disabling/log deletion, clearing HISTFILE, process injection, memory injection into legitimate processes, firewall rule modification
  • Data compression with Gzip/makecab, local staging, exfiltration via custom UDP/TCP C2 on port 45678 or via passive libpcap sniffer
  • Obfuscation of credentials and C2 traffic using XOR, RC4, Base64 encoding
  • Interacting with virtualization hypervisors to harvest guest VM data and vCenter PostgreSQL credentials
  • Use of default accounts for persistence and leveraging remote access tools plus SOCKS proxies

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Command and Control
Collection

ATT&CK Techniques

T1003
T1003.001
T1008
T1014
T1016
T1021
T1021.004
T1027
T1027.005
T1035
T1036
T1036.004
T1037
T1037.004
T1040
T1041
T1070
T1071
T1081
T1083
T1104
T1105
T1124
T1140
T1203
T1205
T1205.001
T1218.011
T1219
T1548
T1554
T1555
T1555.005
T1560
T1560.001
T1560.003
T1562.003
T1571
T1573
T1570
T1574
T1587
T1588.004
T1588.001
T1601
T1673
T1685
T1686

Software / Tooling

TinyShell backdoor
REPTILE rootkit
MEDUSA rootkit
VMware vSphere Installation Bundle (VIB)
esxcli utility
libpcap packet sniffer
SOCKS proxy module
custom UDP/TCP C2 sockets
Backdoor malware

Campaigns & Victims

UNC3886 appears to operate with a long‑term, low‑profile style that prioritizes stealth and persistence. The group favors zero‑day exploits that grant high‑privilege access in highly secure virtualization and networking environments, then installs custom backdoors for ongoing data collection. Victim profiles span a wide spectrum of defense, telecom, utilities, aerospace and critical infrastructure across the US, Japan, Singapore, Russia, Iran and North Korea. Known campaigns include the 2023 exploitation of VMware vCenter CVE‑2023‑34048 to pull credentials from vCenter databases, the deployment of backdoored FortiGate devices in the United States, and a series of attacks on Juniper MX routers using CVE‑2025‑21590 to insert TinyShell backdoors. The actor’s operational tempo is driven more by persistent exploitation opportunities than large‐scale data dumps, resulting in repeated, targeted incursions into high‑value networks.

IOC Patterns

  • Zero‑Day Vulnerability Exploitation (CVE‑2022‑22948, CVE‑2023‑34048, CVE‑2025‑21590)
  • XOR‐encrypted credential files
  • RC4‑encrypted C2 traffic
  • Memory injection into legitimate processes
  • Veriexec bypass via memory injection
  • Script disabling logging on Juniper devices
  • Base64-encoded strings in files
  • Use of port 45678 for C2 communication
  • Clearing HISTFILE environment variable
  • Process ID discovery (snmpd)
  • File names mimicking legitimate binaries (e.g., appid, irad)
  • Rootkit signatures: REPTILE and MEDUSA
  • SOCKS proxy usage
  • Packet sniffing via libpcap

Recommended Actions

  • Apply all available security patches for FortiOS, VMware vCenter, Juniper MX firmware (including CVE‑2025‑21590, CVE‑2023‑20867, CVE‑2022‑22948, and related zero days).
  • Implement strict access controls and least-privilege policies on critical infrastructure services.
  • Deploy runtime protection that detects backdoor deployment patterns and memory injection attempts.
  • Enable comprehensive log monitoring for Juniper routers to detect script-based log tampering.
  • Install integrity verification tools (e.g., veriexec) and monitor for anomalous process injection indicators.
  • Configure IDS/IPS with signatures targeting XOR, RC4‑encrypted traffic, and unexpected ports such as 45678.
  • Segment networks and enforce endpoint detection to limit lateral movement after credential theft.
  • Block or closely monitor outbound UDP/TCP connections originating from Juniper routers and ESXi hosts on default C2 ports.
  • Validate VMware vSphere Installation Bundles (VIBs) for integrity before deployment.
  • Configure network intrusion prevention systems to flag suspicious RC4 traffic and detect hidden SOCKS proxies.
  • Implement comprehensive vulnerability management across all virtualization, networking, and endpoint platforms.

Suggested Tags

China-nexus
Cyberespionage
Zero-Day Exploitation
UNC3886
VMware vCenter attack
Juniper Junos OS backdoor
TinyShell backdoor
Fortinet FortiGate compromise
Credential theft
Defense evasion
Memory injection
Espionage
Network devices
Junos-OS
CVE‑2025‑21590
Rootkit:REPTILE
Rootkit:MEDUSA
SOCKS Proxy
Base64 Encoding
Vulnerability Exploitation
Command and Control

Confidence Assessment

The data supporting the threat profile of UNC3886 comes from multiple reputable security research entities (Mandiant, Palo Alto Unit42, Microsoft Azure Security Blog, SOCPrime). While the technical attribution to a China‑nexus actor is well-supported, the full extent of campaign scope and long‑term persistence remains partially inferred due to limited publicly disclosed incident details. There are gaps in precise operational timelines, the depth of lateral movement across sectors, and confirmed attribution of all observed malware families.

ATT&CK Techniques

Discovery
5 techniques
Execution
8 techniques
Exfiltration
1 technique
Persistence
4 techniques
Resource Development
5 techniques
Stealth
18 techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. Google Cloud Threat Intelligence VMWare ESXi Zero-Day 2023 — Alexander Marvi, Brad Slaybaugh, Ron Craft, and Rufus Brown. (2023, June 13). VMware ESXi Zero-Day Used by Chinese Espionage Actor to Perform Privileged Guest Operations on Compromised Hypervisors. Retrieved March 26, 2025.
  2. Mandiant Fortinet Zero Day — Marvi, A. et al.. (2023, March 16). Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation. Retrieved March 22, 2023.
  3. cloud.google.com — Cited by web research for: CVE-2025-21590
  4. attack.mitre.org — Cited by web research for: T1078
  5. www.trendmicro.com — Cited by web research for: T1219
  6. cloud.google.com — Cited by web research for: REPTILE
  7. unit42.paloaltonetworks.com — Cited by web research for: GTPDOOR
  8. socprime.com — Cited by web research for: Firefox
  9. https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a — Cited by AI analysis.

Intel Summary

75

Techniques

54

Tools

0

Campaigns

40

IOCs

0

Observed Data

15

Tactics

Tags

APT
Zero-Day Exploitation
Cyberespionage
Virtualization Exploits
Zero-day Vulnerabilities
China-Nexus
China-nexus
UNC3886
VMware vCenter attack
Juniper Junos OS backdoor
TinyShell backdoor
Fortinet FortiGate compromise
Credential theft
Defense evasion
Memory injection
Espionage
Network devices
Junos-OS
CVE‑2025‑21590
Rootkit:REPTILE
Rootkit:MEDUSA
SOCKS Proxy
Base64 Encoding
Vulnerability Exploitation
Command and Control

Details

MITRE ID
G1048
Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--461b8e25-8f4a-4ea2-a4a8-e39df7ce6630
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.