logo

UNC3886 Tactics, Techniques, and Procedures: Full Technical Breakdown

ID: e7060775-7afe-5867-b5d0-f7672094aac1

STIX ID: report--e7060775-7afe-5867-b5d0-f7672094aac1

Feed Name: Resources-2

Threat Score
90/100

Date Published: 2025-08-12

Date Updated: 2026-07-22

Author: [email protected] (Sıla Özeren Hacıoğlu)

...
...

UNC3886 is a China-linked APT active in 2025 that targets strategic and critical infrastructure (energy, telecom, healthcare, transportation) across Asia, Europe, and North America; the report details use of zero-day exploits in Fortinet/VMware/Juniper, kernel rootkits and malware families (TinyShell, Melofee, REPTILE) to achieve stealthy persistence, encrypted C2 on non-standard ports, credential theft, and exfiltration, and maps these behaviors to MITRE ATT&CK while demonstrating Picus Platform simulations to expose detection gaps and validate defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.