UNC6586 is a suspected China-nexus cyber-espionage and access-broker threat cluster. It is associated with the SNOWLIGHT downloader/stager, a component used to retrieve and execute follow-on payloads, including VShell. UNC6586 has exploited the critical React Server Components vulnerability CVE-2025-55182 (React2Shell) for initial access, using web-server command execution to download and run SNOWLIGHT. SNOWLIGHT has subsequently retrieved additional payloads through HTTP-based command-and-control communications disguised as legitimate content. The group is one of several China-nexus clusters observed rapidly weaponizing exposed web-application vulnerabilities to establish access to victim environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
26 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A China-nexus access-broker cluster associated with the SNOWLIGHT campaign. The campaign employed cross-platform SNOWLIGHT loaders, public exploit chains, and centralized C2/staging systems in broad attacks against government and commercial infrastructure.
Threat cluster associated with use of the SNOWLIGHT VShell stager.
China-nexus APT cluster referenced as associated with SNOWLIGHT-linked intrusions.
Listed as a threat actor associated in the report’s aggregated section with exploitation activity around React2Shell (CVE-2025-55182) and related RSC/Next.js vulnerabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.