UNC6603 is a China-nexus cyber-espionage threat cluster associated with exploitation of the React Server Components remote code execution vulnerability CVE-2025-55182, also known as React2Shell. The group has been observed using the vulnerability for initial access and then deploying an updated version of the Golang-based HISONIC backdoor to establish persistent remote access on compromised Linux systems. HISONIC communications have been designed to blend with legitimate network activity through abuse of trusted cloud services, reflecting an emphasis on defense evasion and covert post-compromise operations. UNC6603 has been linked to targeting of cloud infrastructure, specifically AWS and Alibaba Cloud instances in the Asia-Pacific region. Reported activity indicates a focus on espionage-oriented access to internet-facing workloads rather than disruptive or extortion-driven operations. The group is one of several China-linked clusters observed rapidly operationalizing newly disclosed vulnerabilities and deploying custom malware families alongside other PRC-aligned actors such as UNC6600, UNC6586, UNC6588, and UNC6595 during React2Shell exploitation. High-confidence behaviors associated with UNC6603 include exploitation of public-facing applications for initial access, deployment of custom backdoors for persistence, use of legitimate cloud platforms to conceal command-and-control traffic, and broader post-exploitation activity on compromised hosts. UNC6603 is publicly tracked under the single known alias UNC6603.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a reported user of the HISONIC backdoor; tooling consistent with post-exploitation persistence/remote access after React2Shell (CVE-2025-55182) exploitation.
Listed as a threat actor associated in the report’s aggregated section with exploitation activity around React2Shell (CVE-2025-55182) and related RSC/Next.js vulnerabilities.
Named in an aggregated list of actors associated with React2Shell (CVE-2025-55182) exploitation activity (UNC-style naming suggests an uncategorized cluster).
China-nexus threat actor exploiting CVE-2025-55182 to deploy updated HISONIC backdoor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.