UNC3804 is a Mandiant-designated uncategorized threat cluster associated with the abuse of legitimate virtual private network, proxy, and localhost tunneling software to conceal operations, blend malicious traffic with normal administrative activity, and maintain remote access. Activity linked to this cluster centers on operational tradecraft rather than a uniquely attributed malware family, emphasizing the use of commercially available or open-source networking tools as covert access and traffic-relay mechanisms. Observed tradecraft associated with UNC3804 includes the use of legitimate VPN and tunneling technologies, renamed binaries to masquerade as benign processes, configuration-file driven deployment, and infrastructure patterns consistent with remote access concealment and encrypted communications. The cluster’s methodology aligns with defense evasion and persistence objectives by leveraging trusted software and common network services instead of bespoke implants alone. Hunting approaches tied to this activity include identifying embedded VPN or proxy artifacts in lure or staging files, detecting renamed VPN components, monitoring suspicious command-line switches and service creation, and correlating network telemetry with known VPN, proxy, or tunnel service behaviors. UNC3804 is best understood as a cluster defined by its operational use of legitimate remote-access and anonymization tooling. Publicly available facts in this context do not establish a confirmed national attribution, victimology, or dominant motivation for the cluster, and no high-confidence ransomware or extortion activity is directly attributed to UNC3804 here.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.