UNC2717 is a China-aligned espionage threat actor targeting global government agencies with advanced tradecraft to steal credentials and intellectual property.
Analyst brief
UNC2717 is a threat actor conducting espionage operations aligned with Chinese government priorities, demonstrating advanced tradecraft to evade detection. They target global government agencies, focusing on stealing credentials, email communications, and intellectual property. Their operations utilize malware such as HARDPULSE, QUIETPULSE, and PULSEJUMP, employing stealthy intrusion methods. Defenders should scrutinize authentication logs for anomalies, monitor email systems for unauthorized access, and focus on detecting the specific TTPs and malware associated with this actor.
UNC2717
unknown
UNC2717 is a threat actor that engages in espionage activities aligned with Chinese government priorities. They demonstrate advanced tradecraft and take measures to avoid detection, making it challenging for network defenders to identify their tools and intrusion methods. UNC2717, along with other Chinese APT actors, has been observed stealing credentials, email communications, and intellectual property. They have targeted global government agencies using malware such as HARDPULSE, QUIETPULSE, and PULSEJUMP.