Skip to content
skopnix
← adversaries
Unknown · assessed origin China

UNC4841

SLIME57
misp-galaxyrefreshed 2026-09-15

sigil

Analyst brief

UNC4841 is a well-resourced threat actor that has utilized a wide range of malware and purpose-built tooling to enable their global espionage operations. They have been observed selectively deploying specific malware families at high priority targets, with SKIPJACK being the most widely deployed. UNC4841 primarily targeted government and technology organizations, but they have also been observed targeting other verticals.

Take it with you
References
Early access

Track UNC4841 on the wire.

Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.

bot-protected