UNC6201 is a suspected People’s Republic of China–linked espionage threat cluster focused on long-term access to enterprise infrastructure, particularly edge appliances, virtualization platforms, and other systems that commonly lack endpoint security visibility. The cluster has been associated with compromises of Dell RecoverPoint for Virtual Machines through CVE-2026-22769 and has also been observed targeting VMware environments and edge devices such as VPN concentrators, routers, and similar network-facing infrastructure. Mandiant has reported notable overlaps with UNC5221, which is often associated with Silk Typhoon, but does not currently assess them as the same cluster. UNC6201 is characterized by stealthy, persistence-oriented post-compromise tradecraft. Reported activity includes lateral movement, long-term persistence, credential capture from compromised appliances, and pivoting from infrastructure devices into broader enterprise and SaaS environments. In VMware environments, the cluster has been observed creating temporary “Ghost NICs” on virtual machines to facilitate covert pivoting, and using iptables-based Single Packet Authorization on compromised vCenter appliances to conceal command-and-control access. Dwell times associated with BRICKSTORM-related intrusions have been reported at nearly 400 days, with average UNC6201 dwell time in some investigations around 393 days. Malware and tooling associated with UNC6201 include the SLAYSTYLE web shell, the BRICKSTORM backdoor, and GRIMBOLT, a C# backdoor compiled with native ahead-of-time techniques to reduce forensic visibility and complicate static analysis. UNC6201 has also modified legitimate startup scripts on compromised appliances to achieve boot persistence. The cluster has been linked to operations against infrastructure layers such as virtualization servers and edge devices specifically because these systems often provide privileged access, facilitate credential interception, and are less likely to be monitored by conventional EDR tooling. Beyond intrusion operations, UNC6201 has also been observed using AI systems for vulnerability research and exploit development, and using automation to provision and cycle premium LLM service accounts at scale. Overall, UNC6201 is best understood as a PRC-nexus cyber-espionage cluster specializing in covert persistence on high-value infrastructure and in leveraging appliance and virtualization compromises to expand access across victim environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cluster lié à la Chine maintenant des accès persistants de très longue durée sur des couches d’infrastructure peu visibles, notamment serveurs de virtualisation et équipements de bordure, à des fins d’espionnage.
Referenced as a PRC-linked threat cluster that exploited Dell RecoverPoint for Virtual Machines zero-day CVE-2026-22769 and delivered BRICKSTORM, GRIMBOLT, and the SLAYSTYLE webshell.
Suspected China-nexus threat cluster linked to attacks using PLENET and exploitation of Dell RecoverPoint for Virtual Machines as a zero-day.
Reported by Google as deploying Brickstorm against Dell RecoverPoint for Virtual Machines.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.