logo

Chinese APT Group Exploits Dell Zero-Day for Two Years

ID: edb0c5e7-7b77-597e-aca2-258ba3994497

STIX ID: report--edb0c5e7-7b77-597e-aca2-258ba3994497

Feed Name: Infosecurity Magazine (News)

Threat Score
92/100

Date Published: 2026-02-18

Date Updated: 2026-04-22

...
...

Dell patched a critical zero-day (CVE-2026-22769) in RecoverPoint for Virtual Machines— a hardcoded-credential issue with a CVSS score of 10.0—after Mandiant reported that UNC6201 (a suspected PRC-linked threat cluster) had been exploiting it since mid-2024 to gain root access, maintain persistence, move laterally, and deploy backdoors and other malware (Grimbolt, Brickstorm, Slaystyle); the report also describes novel TTPs targeting VMware environments (ghost NICs) and use of iptables for single-packet authorization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.