UNC3886 is an advanced cyber espionage group targeting firewall and virtualization technologies without EDR support.
Analyst brief
UNC3886 is an advanced cyber espionage group. They primarily target firewall and virtualization technologies lacking EDR support. Their TTPs include exploiting public-facing applications, using custom malware (e.g., VIRTUALPITA, MOPSLED), and executing commands via Hypervisor CLI. Defenders should monitor for default account usage in ESXi environments, non-standard C2 protocols (Non-Application Layer Protocol), and script-based discovery activities.
UNC3886
unknown
UNC3886 is an advanced cyber espionage group with unique capabilities in how they operate on-network as well as the tools they utilize in their campaigns. UNC3886 has been observed targeting firewall and virtualization technologies which lack EDR support. Their ability to manipulate firewall firmware and exploit a zero-day indicates they have curated a deeper-level of understanding of such technologies. UNC3886 has modified publicly available malware, specifically targeting *nix operating systems.
Monitor system logs and command history for preventing command history logging.
FAQ2
What kind of technologies does UNC3886 primarily target?+
UNC3886 primarily targets firewall and virtualization technologies that lack EDR support.
What signals should defenders look for to detect UNC3886 activity?+
Defenders should monitor for default account usage in ESXi environments, non-standard C2 protocols (Non-Application Layer Protocol), and script-based discovery activities.