UNC2630 is a Chinese-affiliated cyber espionage group targeting Pulse Secure VPN appliances.
Analyst brief
UNC2630 is a threat group believed to be affiliated with the Chinese government conducting cyber espionage. They target organizations aligned with Beijing's strategic objectives. Their key TTPs include using SLOWPULSE and RADIALPULSE malware to compromise Pulse Secure VPN appliances, leveraging modified binaries and scripts for persistence and lateral movement. Defenders should focus on monitoring Pulse Secure VPN access and detecting unauthorized binary modifications.
UNC2630
unknown
UNC2630 is a threat actor believed to be affiliated with the Chinese government. They engage in cyber espionage activities, targeting organizations aligned with Beijing's strategic objectives. UNC2630 demonstrates advanced tradecraft and employs various malware families, including SLOWPULSE and RADIALPULSE, to compromise Pulse Secure VPN appliances. They also utilize modified binaries and scripts to maintain persistence and move laterally within compromised networks.