Home · Wiki · Entities & Threat Actors
created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: high · affected_sectors: [] · au_impact: false

UNC3886

UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan (APJ) regions. UNC3886 has displayed a deep understanding of edge devices and virtualization technologies through the exploitation of zero-day vulnerabilities and the use of novel malware families and utilities.

Attribute Detail
ATT&CK ID G1048
Aliases
Attribution China
Class state
Active since 2022 (per ATT&CK description)
ATT&CK entry created 2025-05-29
Techniques mapped 57

Attribution — as claimed

Stated by MITRE ATT&CK (state attribution).

Known TTPs

Technique Name
T1003.001 LSASS Memory
T1008 Fallback Channels
T1014 Rootkit
T1021.004 SSH
T1027.005 Indicator Removal from Tools
T1036.004 Masquerade Task or Service
T1037 Boot or Logon Initialization Scripts
T1037.004 RC Scripts
T1040 Network Sniffing
T1057 Process Discovery
T1059.001 PowerShell
T1059.003 Windows Command Shell

(First 12 of 57 ATT&CK-mapped techniques.)

Related Pages

  • Mitre Attack — the framework this page's data is drawn from
  • Ke3Chang — China-linked actor, same attribution class
  • Mustang Panda — China-linked actor, same attribution class
  • Earth Lusca — China-linked actor, same attribution class

Provenance

Stub generated from MITRE ATT&CK G1048 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.