UNC4191 is a China-nexus cyberespionage threat actor tracked for operations affecting public- and private-sector entities primarily in Southeast Asia, with activity also extending to the Philippines, the United States, Europe, and the broader Asia-Pacific and Japan region. The actor is associated with espionage-oriented intrusions consistent with broader Chinese state-aligned intelligence collection priorities. Reported targeting indicates a strong focus on government and other strategically relevant organizations in Southeast Asia, especially the Philippines, while also reaching victims in Western and regional partner countries. UNC4191 is assessed as part of the wider Chinese intrusion ecosystem characterized by persistent intelligence collection, regional geopolitical targeting, and operations aligned with state interests. High-confidence reporting in the available material supports a China nexus and an espionage motivation, but does not provide sufficiently specific, corroborated detail on distinct malware families, sub-groups, or a fuller set of actor-specific tactics beyond its cyberespionage targeting footprint. No additional widely used aliases are established in the available information beyond UNC4191.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
UNC4191 is a China-nexus intrusion set focused on cyberespionage against government and strategic entities in Southeast Asia, Europe, and the US.
UNC4191 is conducting cyber espionage campaigns using USB devices as an initial access vector, primarily targeting public and private sector entities in Southeast Asia, especially the Philippines, for intelligence collection related to China's political and commercial interests.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.