UNC251 is a tracked intrusion cluster with assessed links to People’s Republic of China (PRC)-nexus activity. Available reporting ties it to other PRC-linked clusters through shared infrastructure characteristics, naming conventions, certificates, and tooling overlap, indicating participation in a broader Chinese intrusion ecosystem rather than an isolated actor. UNC251 has been associated with malware and tradecraft involving shell and attack tooling, and has been linked analytically to overlaps with clusters such as UNC3569 and UNC3246. High-confidence public detail on UNC251’s independent victimology, organizational structure, and full operational scope remains limited. Based on the available evidence, UNC251 is best characterized as a PRC-linked intrusion cluster connected to broader Chinese contractor or state-aligned cyber activity, with observed use or association of post-compromise tooling consistent with backdoor deployment and interactive shell access.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.