UNC3569 is a prolific China-nexus espionage threat actor operating largely from China and assessed to sit within the broader Chinese cybercriminal and contractor-for-hire ecosystem. The group has conducted global intrusions with a concentration in East and Southeast Asia, while also targeting organizations in the United States and elsewhere. Reported victim sectors include government, education, technology, finance, media, telecommunications, airlines, heavy industry, energy, and the gambling industry. UNC3569 is notable for repeatedly exploiting known vulnerabilities in internet-facing enterprise software to obtain initial access, including products from Apache, Microsoft, IBM, VMware, Oracle, Aspera Faspex, Microsoft Exchange, and Oracle Web Applications Desktop Integrator. After compromise, the actor has used tooling such as OXEEYE and the SIDESTEP launcher for post-exploitation access and reconnaissance, followed by Cobalt Strike BEACON and a set of custom backdoors including DRAFTGRAPH, CROSSWALK, and GRAYRABBIT. Additional loaders and evasion components associated with the actor include RABBITCAVE, AtomLdr, RABBITFUR, RABBITMOUND, RABBITNEST, RABBITASH, and RABBITWING. UNC3569 has also been linked to cloud- and supply-chain-enabled operations, abuse of legitimate platforms such as GitHub and OneDrive for payload delivery or command and control, and use of commercial Chinese remote-control software and public offensive tooling. Observed tradecraft includes reconnaissance, exploitation of public-facing applications, deployment of backdoors and port-forwarding tools, lateral movement, credential and browser-data theft, cookie theft, persistence, and defense evasion. In supply-chain-related activity, the actor used trojanized software and custom tooling to collect system information, browser data, messaging-app data, and screenshots. UNC3569 has also been associated with campaigns targeting the Chinese gambling sector and has infrastructure and malware overlaps with activity tracked as SHADOW-VOID-044, including GRAYRABBIT usage. Reporting has further noted links between UNC3569 and other PRC-nexus clusters such as UNC251 and UNC3246 through shared infrastructure traits and tooling overlap. Available evidence supports classifying UNC3569 primarily as a Chinese espionage actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
33 malware families attributed to this actor across reporting.
28 additional families tracked in Mallory.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
Delivered scripts observed include CVE-2020-16040 exploitation for Chrome, social engineering pop-ups, Electron JS backdoor delivery, and TCP reverse shell establishment.
Download multiple ProxyShell exploit tools for testing: Proxyshell-auto ... Exploit tool based on CVE-2021-34473, CVE-2021-31206, CVE-2021-34523, CVE-2021-31207 ... proxyshell ... based on the Microsoft Exchange CVE-2021-34473, CVE-2021-34523, CVE-2021-31207.
Since 2021, UNC3569 has exploited popular n-day CVEs in widely used software, such as CVE-2021-44228 and CVE‑2022-21587, to gain access to target organizations.
Since 2021, UNC3569 has exploited popular n-day CVEs in widely used software, such as CVE-2021-44228 and CVE‑2022-21587, to gain access to target organizations.
In February 2023, UNC3569 targeted a US media and entertainment company, exploiting CVE-2022-47986, which allowed the attackers to execute arbitrary commands on the Aspera Faspex server.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the likely attribution for SHADOW-VOID-044 based on shared GRAYRABBIT infrastructure, overlapping C2 domain usage, and common targeting of the Chinese gambling industry.
Assessed as linked (moderate-to-high confidence) to the SHADOW-VOID-044 campaign leveraging PeckBirdy and associated infrastructure; described as targeting the gambling sector.
Named activity cluster referenced due to infrastructure overlap (a C2 domain) with Shadow-Void-044; no additional operational details provided in the content.
China-backed cluster associated (in this reporting) with use of the GrayRabbit backdoor; mentioned in the context of the Shadow-Earth-045 campaign toolset.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.