PLA Unit 61486 is referenced as a China-linked advanced persistent threat designation and is also identified as APT2. It is associated with the broader category of long-term, stealthy intrusion activity typically conducted for strategic intelligence collection. Advanced persistent threat operations attributed to Chinese military-linked units have historically focused on gaining unauthorized access to victim networks, maintaining long dwell time, escalating privileges, conducting internal reconnaissance, moving laterally, preserving persistence, and completing missions through data exfiltration. Common tradecraft associated with such operations includes targeted social engineering, spearphishing, deployment of custom malware, low-and-slow operational behavior, and efforts to evade detection while retaining access over extended periods. The available information supports characterization of PLA Unit 61486 as a state-linked espionage actor designation, but provides limited actor-specific detail beyond the alias APT2.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a China-linked APT group/unit; no additional operational detail provided in the content beyond inclusion in an APT group list.
PLA Unit 61486
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.