Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC215

Description

UNC215 is a Chinese nation-state threat actor that has been active since at least 2014. They have targeted organizations in various sectors, including government, technology, telecommunications, defense, finance, entertainment, and healthcare. UNC215 has been observed using tools such as Mimikatz, FOCUSFJORD, and HYPERBRO for initial access and post-compromise activities. They have demonstrated a focus on evading detection and have employed tactics such as using trusted third parties, minimizing forensic evidence, and incorporating false flags. UNC215's targets are located globally, with a particular focus on the Middle East, Europe, Asia, and North America.

AI Analysis

· 1 week ago

Executive Summary

UNC215 is identified as a Chinese nation-state threat actor that has been active since at least 2014. They primarily target multiple sectors including government, technology, telecommunications, defense, finance, entertainment, and healthcare. Their activities are characterized by the use of sophisticated tools such as Mimikatz, FOCUSFJORD, and HYPERBRO for initial access and post-compromise operations. UNC215 employs evasion techniques to avoid detection, leveraging trusted third parties, minimizing forensic evidence, and incorporating false flags.

Goals & Targeting

UNC215's strategic objectives appear to align with those of a Chinese state-sponsored actor, focusing on economic and military espionage to support national interests. By targeting diverse sectors such as defense, government, and technology, the group likely seeks to accumulate sensitive information, technological advancements, and geopolitical intelligence. Their global reach, particularly in regions with strategic or economic significance, underscores an intent to maximize their intelligence yield without being constrained by geographic limitations.

Enhanced Description

UNC215 is a Chinese nation-state threat actor known for targeting organizations across various sectors globally. Their operations have been ongoing since at least 2014, with victims located in the Middle East, Europe, Asia, and North America. This group demonstrates a high level of sophistication in their tactics, techniques, and procedures (TTPs), focusing on evading detection by using trusted third parties for initial access and employing false flags to misdirect investigations. The tools associated with UNC215 include Mimikatz, which is commonly used for credential extraction; FOCUSFJORD, a suspected espionage tool; and HYPERBRO, likely utilized as an implant for persistence and data exfiltration. Their strategic targeting of critical sectors suggests a primary motivation tied to intelligence gathering and potentially economic or military advantage.

Key Capabilities

  • Spear-phishing campaigns using malicious attachments
  • Credential extraction via Mimikatz
  • Implant deployment for persistent access
  • Use of trusted third-party relationships for initial access
  • False flag operations to misattribute attacks
  • Evasion techniques to minimize forensic evidence

MITRE ATT&CK Tactics

Initial Access
Execution
Credential Access
Discovery
Lateral Movement
Collection

ATT&CK Techniques

T1059.003 - Windows Local Job Scheduling: IIS Crypto Module Configuration Command-Line
T1021.004 - Remote Services Session Hijacking: RDP
T1078.001 - Account Access Removal/Modification: Credential Dumping via Registry
T1566.001 - Collection Activities: Data Exfiltration

Software / Tooling

Mimikatz
FOCUSFJORD
HYPERBRO

Campaigns & Victims

UNC215's campaigns are characterized by their persistence and global reach. The group has demonstrated a preference for long-term operations, often establishing persistent access to networks before extracting valuable intelligence. Their use of false flags suggests an attempt to misdirect attribution efforts, possibly to avoid direct confrontation or to shift blame elsewhere. Notable past operations have targeted high-value sectors, reflecting a strategic focus on maximizing the impact of their activities.

IOC Patterns

  • Spear-phishing emails with malicious Office documents
  • Lateral movement across internal networks using remote services
  • Credential dumping via Windows registry keys or LSASS memory extraction
  • Data exfiltration via encrypted channels or legitimate third-party services

Recommended Actions

  • Implement robust endpoint detection and response (EDR) solutions to detect and respond to such tactics.
  • Conduct regular security training to mitigate spear-phishing attempts and raise awareness among employees.
  • Monitor network traffic for signs of lateral movement and data exfiltration activities, including encrypted communications.
  • Apply strong access controls and regularly review user accounts for unauthorized access or privileges.

Suggested Tags

APT
nation-state
espionage
economic espionage

Confidence Assessment

Moderate confidence in the characterization of UNC215 exists, based on available open-source intelligence. The actor's tools and TTPs are known, but detailed specifics about their exact impact and precise motivations remain unclear. Further data, particularly from private or classified sources, would enhance understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Healthcare Targeting
Critical Infrastructure
Government Targeting
nation-state
espionage
economic espionage

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.