UNC2814 is a suspected People’s Republic of China-nexus cyber-espionage group tracked since at least 2017. It has conducted a long-running global campaign against telecommunications operators and government entities, with confirmed compromises of 53 organizations in 42 countries and additional suspected infections elsewhere. Its telecom-focused targeting includes systems holding subscriber personally identifiable information, call records, and SMS-related data, consistent with surveillance-oriented intelligence collection. UNC2814 is assessed to be distinct from Salt Typhoon. The group uses the custom Linux backdoor GRIDTIDE, a C-based implant that executes shell commands, transfers files, and profiles compromised hosts. GRIDTIDE abuses legitimate Google Sheets API functionality for command-and-control, enabling tasking and host-data exchange through cloud-service traffic that can resemble ordinary SaaS activity. UNC2814 has compromised internet-facing web servers and edge systems, moved laterally through SSH using service accounts, employed living-off-the-land utilities for reconnaissance, privilege escalation, and persistence, and deployed SoftEther VPN Bridge for encrypted outbound tunneling. It establishes persistence using systemd services. No sensitive-data exfiltration was directly observed in the documented GRIDTIDE campaign. UNC2814 has also used persona-driven prompts against generative-AI systems to support vulnerability research involving embedded-device firmware and Odette File Transfer Protocol implementations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
57 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
245 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PRC-linked actor using AI personas to bypass model safety guardrails and accelerate vulnerability research against firmware and file transfer software.
Uses AI models to bypass safety guardrails and assist vulnerability research against TP-Link firmware and Odette File Transfer Protocol implementations.
Using AI systems for exploit development and vulnerability research.
Conducting cyberespionage activity and using jailbreak prompts against Gemini to analyze TP-Link firmware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.