UNC5266 is a suspected China-nexus cyber espionage actor targeting high-value organizations for intelligence gathering.
Analyst brief
UNC5266 is a suspected China-nexus cyber espionage actor tracked for post-disclosure exploitation activities. It primarily targets high-value organizations, including cybersecurity firms, for intelligence gathering. Key TTPs include deploying the SLIVER implant framework, a WARPWIRE variant, and the new TERRIBLETEA malware after exploiting public-facing application vulnerabilities. Defenders should prioritize patching known vulnerabilities in Aspera Faspex and Microsoft Exchange, and monitor for SLIVER C2 beaconing and TERRIBLETEA execution artifacts.
UNC5266
unknown
Mandiant created UNC5266 to track post-disclosure exploitation leading to deployment of Bishop Fox's SLIVER implant framework, a WARPWIRE variant, and a new malware family that Mandiant has named TERRIBLETEA. At this time, based on observed infrastructure usage similarities, Mandiant suspects with moderate confidence that UNC5266 overlaps in part with UNC3569, a China-nexus espionage actor that has been observed exploiting vulnerabilities in Aspera Faspex, Microsoft Exchange, and Oracle Web Applications Desktop Integrator, among others, to gain initial access to target environments.