UNC6201 is a suspected PRC-nexus espionage threat cluster associated with long-duration intrusions against edge appliances, virtualization infrastructure, and enterprise recovery platforms. The actor has been publicly linked to exploitation of CVE-2026-22769 in Dell RecoverPoint for Virtual Machines as a zero-day since at least mid-2024, using that access to obtain root-level control of appliances, move laterally, maintain persistence, and pivot into VMware environments. Reporting also describes UNC6201 as targeting edge devices that typically lack endpoint security visibility, including appliances such as VPN concentrators, and using compromised infrastructure to capture valid credentials and sustain covert access for extended periods. Observed UNC6201 tooling includes the SLAYSTYLE web shell, the BRICKSTORM backdoor, and the newer GRIMBOLT backdoor. GRIMBOLT is described as a C# foothold backdoor compiled with native ahead-of-time techniques and packed to complicate static analysis, and it has been observed replacing older BRICKSTORM deployments in later activity. The cluster has used persistence mechanisms on compromised appliances by modifying legitimate startup-related scripts, and has employed stealth-focused post-compromise tradecraft in VMware environments, including temporary “Ghost NIC” creation for pivoting and iptables-based Single Packet Authorization on compromised vCenter appliances to conceal command-and-control access. UNC6201 is notable for focusing on systems that provide privileged access into broader enterprise environments, especially network edge and virtualization management layers. Incident reporting ties the actor to compromise of VMware-related infrastructure and backup or disaster recovery systems, making its operations strategically significant for both espionage access and resilience degradation. Mandiant reporting cited average dwell times of roughly 393 days in incidents involving this cluster, underscoring its emphasis on persistence and low-visibility operations. The cluster has notable overlaps with UNC5221, which is publicly associated with Silk Typhoon, but available reporting does not currently assess UNC6201 and UNC5221 to be the same cluster. UNC6201 has also been observed using AI-related tooling operationally, including use of AI systems for vulnerability research and exploit development, as well as automation to obtain access to premium large-language-model services through scripted account lifecycle abuse. Overall, UNC6201 is best characterized as a sophisticated China-linked espionage actor specializing in exploitation of edge and appliance technologies, long-term persistence, credential access, and stealthy expansion into virtualized enterprise environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a PRC-linked threat cluster that exploited Dell RecoverPoint for Virtual Machines zero-day CVE-2026-22769 and delivered BRICKSTORM, GRIMBOLT, and the SLAYSTYLE webshell.
Suspected China-nexus threat cluster linked to attacks using PLENET and exploitation of Dell RecoverPoint for Virtual Machines as a zero-day.
Reported by Google as deploying Brickstorm against Dell RecoverPoint for Virtual Machines.
PRC-linked cluster automating large-scale acquisition and churn of disposable premium AI accounts to sustain adversary LLM access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.