Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC2717

Description

UNC2717 is a threat actor that engages in espionage activities aligned with Chinese government priorities. They demonstrate advanced tradecraft and take measures to avoid detection, making it challenging for network defenders to identify their tools and intrusion methods. UNC2717, along with other Chinese APT actors, has been observed stealing credentials, email communications, and intellectual property. They have targeted global government agencies using malware such as HARDPULSE, QUIETPULSE, and PULSEJUMP.

AI Analysis

· 1 week ago

Executive Summary

UNC2717 is a sophisticated threat actor engaging in espionage activities aligned with Chinese government priorities. They are known for advanced tradecraft and evasive tactics, targeting global government agencies to steal sensitive information such as credentials and intellectual property.

Goals & Targeting

UNC2717 appears to focus on advancing Chinese government interests through espionage activities. Their primary targets include global government agencies, likely to gain access to diplomatic and military communications. The group's goal is to collect sensitive information such as credentials, email communications, and intellectual property, which could be used for strategic advantage.

Enhanced Description

UNC2717 is a state-sponsored Advanced Persistent Threat (APT) group that has demonstrated a high level of technical expertise and operational discipline. Their activities are primarily focused on espionage, with a particular emphasis on stealing sensitive data from government agencies and private sector entities. They have been observed using sophisticated malware families such as HARDPULSE, QUIETPULSE, and PULSEJUMP to infiltrate victims' networks. These tools are designed to avoid detection, making UNC2717 a challenging threat for network defenders. The group's targeting strategy is aligned with Chinese strategic interests, suggesting they may be part of a broader effort to gather intelligence that could benefit national security objectives.

Key Capabilities

  • Advanced persistent threat (APT) capabilities
  • Spear-phishing campaigns with malware-laced emails
  • Malware development and deployment
  • C2 infrastructure using DNS for communication
  • Credential harvesting
  • Lateral movement within networks
  • Exfiltration of data

MITRE ATT&CK Tactics

Initial Access
Defense Evasion
credential Access
Discovery
Lateral Movement
Exfiltration
Impact

ATT&CK Techniques

T1563.001
T1057.002
T1055
T1505.004
T1003.001
T1059.003
T1078.001

Software / Tooling

HARDPULSE
QUIETPULSE
PULSEJUMP

Campaigns & Victims

UNC2717 has been active for several years, with campaigns targeting government agencies globally. Their operational tempo is methodical, with a focus on long-term access and data exfiltration. Notable past operations include the use of HARDPULSE malware to compromise victim systems, followed by the deployment of additional tools for persistence and lateral movement. The group's ability to adapt their tactics and evade detection makes them a significant threat.

IOC Patterns

  • Spear-phishing emails with malicious attachments or links
  • Malware droppers masquerading as legitimate files
  • C2 communication over DNS channels
  • Presence of custom malware such as HARDPULSE, QUIETPULSE, and PULSEJUMP
  • Staging infrastructure hosted on compromised servers

Recommended Actions

  • Implement multi-layered email filtering to detect phishing attempts.
  • Monitor for unusual network traffic and DNS queries unrelated to normal business operations.
  • Conduct regular updates of software and patch management programs.
  • Use endpoint detection and response (EDR) tools to identify and block malicious activities.
  • Strengthen authentication mechanisms and implement multi-factor authentication (MFA).

Suggested Tags

APT
espionage
government
malware

Confidence Assessment

The available data regarding UNC2717 indicates high confidence in their APT capabilities, targeting strategies, and use of specific tools. However, gaps exist in understanding the full scope of their toolset and potential origins beyond Chinese state involvement.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Government Targeting
espionage
government
malware

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.