UNC3886 is a China-nexus espionage threat actor known for highly targeted intrusions against strategic sectors, including defense and aerospace, and for campaigns that abuse edge devices and network appliances as an initial access vector. The group has been associated with operations consistent with state-sponsored intelligence collection and is notable for emphasizing stealth, privileged access, and long-term persistence in victim environments. UNC3886 has been linked to activity targeting organizations of geopolitical and military interest, particularly entities whose technology, research, or supply chains support defense missions. Reporting has highlighted the actor as part of a broader pattern of Chinese intrusion activity against the defense industrial base, where access to edge infrastructure and appliances is used to bypass traditional endpoint visibility and establish footholds in sensitive networks. Tradecraft associated with UNC3886 includes exploitation for privilege escalation, process injection, PowerShell execution, and the use of proxying or multi-hop command-and-control techniques to obscure operator infrastructure and movement. The actor has been observed in contexts mapped to ATT&CK techniques such as Exploitation for Privilege Escalation, Process Injection, PowerShell, Setuid and Setgid abuse, Windows Service persistence, and Multi-hop Proxy. This combination of techniques reflects an operator focused on defense evasion, privileged execution, and resilient access across both Linux and Windows environments. UNC3886 is also referred to as Fire Ant. The available information supports characterizing the group as a China-aligned threat actor engaged in sophisticated cyber espionage, with particular relevance to campaigns involving edge-device compromise, appliance-focused intrusion paths, and post-exploitation activity designed to maintain covert access in high-value enterprise networks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 malware families attributed to this actor across reporting.
15 additional families tracked in Mallory.
24 CVEs this actor has used in observed campaigns. 24 of them exploited in the wild.
After compromising the hypervisor, the Fire Ant actors exploited another vulnerability — CVE-2023-20867 — to execute commands inside the guest virtual machines (VMs) without the required authentication. CVE-2023-20867 is an authentication bypass flaw that was also exploited by UNC3886 and disclosed by Mandiant researchers in 2023.
Sygnia's investigation into the cyberespionage campaign found that Fire Ant actors exploited a nearly two-year-old vulnerability in VMware vCenter, tracked as CVE-2023-34048, to gain initial access to targeted organizations.
During RedPenguin, UNC3886 exploited CVE-2025-21590 to enable malicious code injection into the memory of legitimate processes.
UNC3886 has used zero-day vulnerabilities CVE-2022-41328 against FortiOS and CVE-2023-20867 and CVE-2023-34048 against VMware vCenter.
The abuse of CVE-2022-22948, on the other hand, has been attributed by Google-owned Mandiant to a China-nexus cyber espionage group known as UNC3886...
19 more CVEs tied to this actor tracked in Mallory.
36 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a covert espionage operation by placing backdoors in virtual machines and collecting data for months while remaining undetected.
Mentioned only as an annotated threat actor associated with the ATT&CK technique Process Injection (T1055) in a Splunk detection entry; no campaign or activity is described.
Mentioned only as an annotation/tag associated with the ATT&CK technique Process Injection (T1055); no campaign or activity by this group is described in the content.
Mentioned only in an annotation/list associated with the detection content; no actor-specific activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.