logo

UNC3886 Uses Fortinet, VMware 0-Days and Stealth Tactics in Long-Term Spying

ID: 93b4df92-b9da-5385-bc2e-c685c30d6a09

STIX ID: report--93b4df92-b9da-5385-bc2e-c685c30d6a09

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-06-19

Date Updated: 2026-05-06

Author: [email protected] (The Hacker News)

...
...

UNC3886, a China-nexus cyber espionage actor, has been observed exploiting multiple zero-day vulnerabilities in Fortinet and VMware products to establish persistent access across victims in North America, Southeast Asia, Oceania and other regions; the actor uses VM-targeted rootkits (Reptile, Medusa), backdoors (MOPSLED, RIFLESPINE), backdoored SSH/TACACS tools for credential harvesting, and cloud services (GitHub, Google Drive) as C2 channels, prompting organizations to follow Fortinet and VMware advisories to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.