UNC6588 is a China-aligned cyber-espionage threat cluster tracked for exploitation of server-side web application vulnerabilities to gain initial access and deploy Linux backdoors. The group has been observed exploiting CVE-2025-55182, also known as React2Shell, against applications using React Server Components and related frameworks, and then downloading the COMPOOD backdoor, also referred to as Pood or Compood. COMPOOD has been associated with suspected China-nexus espionage activity since at least 2022. UNC6588 is part of a broader set of China-linked intrusion clusters observed rapidly operationalizing newly disclosed internet-facing vulnerabilities. In the React2Shell activity, the actor used the vulnerability for unauthenticated remote code execution, followed by payload retrieval and execution to establish persistent access on compromised Linux systems. Reported behavior supports initial access, persistence, post-exploitation, and defense-evasion tradecraft typical of espionage operations focused on maintaining covert footholds on exposed infrastructure. The actor is assessed as espionage-motivated. High-confidence reporting links UNC6588 to Chinese cyber-espionage activity, but no more specific organizational attribution is established here. Public reporting in this context does not provide a reliable victim-country or sector breakdown specific to UNC6588 alone, beyond its use of infrastructure-facing exploitation and deployment of an espionage-associated backdoor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated in the report’s aggregated section with exploitation activity around React2Shell (CVE-2025-55182) and related RSC/Next.js vulnerabilities.
Named in an aggregated list of actors associated with React2Shell (CVE-2025-55182) exploitation activity (UNC-style naming suggests an uncategorized cluster).
China-nexus threat actor exploiting CVE-2025-55182 to deploy COMPOOD backdoor.
UNC6588 is a China-nexus threat actor group exploiting the React2Shell vulnerability to deliver the backdoor COMPOOD.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.