UNC2814 is a suspected People’s Republic of China–nexus cyber espionage group tracked since at least 2017. The actor has conducted a long-running global espionage campaign primarily targeting telecommunications providers and government organizations across Africa, Asia, the Americas, and Europe. Reporting attributes at least 53 confirmed victims in 42 countries, with additional suspected infections in more than 20 other countries. UNC2814 has been assessed as distinct from Salt Typhoon, with no observed overlap in victims or tradecraft. A defining feature of UNC2814’s operations is the use of the GRIDTIDE backdoor, a C-based implant capable of executing arbitrary shell commands and transferring files. GRIDTIDE abuses legitimate cloud application APIs for command and control, notably using Google Sheets API functionality so malicious traffic blends with normal SaaS activity rather than relying on exploitation of the cloud provider itself. The group has also used SoftEther VPN Bridge to maintain encrypted outbound connectivity. Observed post-compromise tradecraft includes use of service accounts and SSH for lateral movement, living-off-the-land binaries for reconnaissance, privilege escalation, and persistence, and creation of systemd services to maintain access. UNC2814 has targeted systems containing highly sensitive personally identifiable information, consistent with telecommunications-focused surveillance objectives such as identifying, tracking, and monitoring persons of interest. Historical assessments of comparable PRC telecom intrusions indicate interest in communications metadata and related surveillance-enabling data. UNC2814 has also been observed using generative AI systems to support vulnerability research and exploit development workflows. Reported activity includes persona-driven jailbreaking prompts intended to bypass model safety guardrails during analysis of embedded-device firmware and Odette File Transfer Protocol implementations. An alias association with Gallium appears in some reporting, but the strongest high-confidence identifier in current reporting is UNC2814.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
227 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PRC-linked actor using AI personas to bypass model safety guardrails and accelerate vulnerability research against firmware and file transfer software.
Uses AI models to bypass safety guardrails and assist vulnerability research against TP-Link firmware and Odette File Transfer Protocol implementations.
Using AI systems for exploit development and vulnerability research.
Conducting cyberespionage activity and using jailbreak prompts against Gemini to analyze TP-Link firmware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.