Also known as: tracked as, CVE-2025-21590
UNC3886 is a sophisticated China‑linked espionage group that has conducted targeted attacks on high-value infrastructure since at least 2022. The actor demonstrates deep knowledge of edge networking equipment and virtualization technologies, exploiting multiple zero‑day vulnerabilities—most notably CVE‑2023‑34048 in VMware vCenter, CVE‑2025‑21590 in Juniper MX routers, and Fortinet CVEs such as CVE‑2023‑34048—to gain unauthenticated remote command execution and bypass veriexec protections. Once inside the network, UNC3886 deploys a suite of custom backdoors: TinyShell on Juniper devices, REPTILE and MEDUSA rootkits on Windows/Unix guests, and malicious VMware vSphere Installation Bundles (VIBs) that persist through ESXi host reboots. The group also installs backdoored SSH daemons, uses esxcli to modify firewall rules, and removes logs via script manipulation and memory injection into legitimate processes. Data exfiltration is performed in stages—credentials are XOR‑encrypted or stored using RC4, files are compressed with Gzip/makecab, staged locally on the compromised device, then transmitted over custom UDP/TCP sockets (default port 45678) or via hidden libpcap packet‑sniffing modules. The malware consistently obfuscates its traffic and clears shell history (HISTFILE). Overall, UNC3886’s toolkit blends publicly known exploitation mechanisms with bespoke, long‑lived persistence vectors to maintain stealth across virtualized environments.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC3886 is a China‑nexus cyberespionage actor that has been active since at least 2022, targeting defense, telecom, and critical infrastructure organizations worldwide, including the United States, Japan, Singapore and Russia. The group leverages zero‑day vulnerabilities in VMware vCenter, Fortinet FortiGate, and Juniper MX routers to deploy custom backdoors (TinyShell, REPTILE, MEDUSA) and establish long‑term persistence on edge devices and hypervisors. Its operations combine credential theft, data staging, obfuscated C2 channels, and extensive defense‑evasion techniques to exfiltrate intelligence from privileged IT environments.
Goals & Targeting
UNC3886 conducts espionage aimed at acquiring strategic intelligence from defense, governmental, telecommunications, aviation, aerospace, and critical infrastructure sectors. By targeting edge routers and hypervisors that sit between service providers and enterprise networks, the group gains privileged visibility into vast amounts of operational data. The attacker’s preference for zero‑day vulnerabilities and custom backdoors indicates an objective to remain undetected over long periods while gathering actionable intelligence from highly protected environments.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC3886 appears to operate with a long‑term, low‑profile style that prioritizes stealth and persistence. The group favors zero‑day exploits that grant high‑privilege access in highly secure virtualization and networking environments, then installs custom backdoors for ongoing data collection. Victim profiles span a wide spectrum of defense, telecom, utilities, aerospace and critical infrastructure across the US, Japan, Singapore, Russia, Iran and North Korea. Known campaigns include the 2023 exploitation of VMware vCenter CVE‑2023‑34048 to pull credentials from vCenter databases, the deployment of backdoored FortiGate devices in the United States, and a series of attacks on Juniper MX routers using CVE‑2025‑21590 to insert TinyShell backdoors. The actor’s operational tempo is driven more by persistent exploitation opportunities than large‐scale data dumps, resulting in repeated, targeted incursions into high‑value networks.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The data supporting the threat profile of UNC3886 comes from multiple reputable security research entities (Mandiant, Palo Alto Unit42, Microsoft Azure Security Blog, SOCPrime). While the technical attribution to a China‑nexus actor is well-supported, the full extent of campaign scope and long‑term persistence remains partially inferred due to limited publicly disclosed incident details. There are gaps in precise operational timelines, the depth of lateral movement across sectors, and confirmed attribution of all observed malware families.
No campaigns linked yet.
No observed data linked yet.
75
Techniques
54
Tools
0
Campaigns
40
IOCs
0
Observed Data
15
Tactics