UNC6201 is a Chinese state-sponsored threat actor using Single Packet Authorization and Port Knocking to deploy backdoors at the Virtualization Layer.
Analyst brief
UNC6201 is a sophisticated Chinese state-sponsored threat actor. It targets Dell RecoverPoint for Virtual Machines appliances by exploiting vulnerabilities such as CVE-2026-22769. To ensure persistence, it deploys backdoors using Single Packet Authorization and Port Knocking techniques while operating at the Virtualization Layer to evade OS-level detection. Defenders should prioritize patching affected appliances and monitoring virtualization-layer activities for anomalous patterns.
UNC6201
unknown
UNC6201 is a sophisticated Chinese state-sponsored hacking group that exploited CVE-2026–22769, a critical vulnerability in Dell RecoverPoint for Virtual Machines appliances, to establish a persistent presence. They deployed a permanent backdoor using techniques like Single Packet Authorization and "Port Knocking." Unlike typical hackers who conceal their activities within the Operating System, UNC6201 operated at the Virtualization Layer to avoid detection.