created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: high · affected_sectors: [] · au_impact: false
UNC3886
UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan (APJ) regions. UNC3886 has displayed a deep understanding of edge devices and virtualization technologies through the exploitation of zero-day vulnerabilities and the use of novel malware families and utilities.
| Attribute | Detail |
|---|---|
| ATT&CK ID | G1048 |
| Aliases | — |
| Attribution | China |
| Class | state |
| Active since | 2022 (per ATT&CK description) |
| ATT&CK entry created | 2025-05-29 |
| Techniques mapped | 57 |
Attribution — as claimed
Stated by MITRE ATT&CK (state attribution).
Known TTPs
| Technique | Name |
|---|---|
T1003.001 |
LSASS Memory |
T1008 |
Fallback Channels |
T1014 |
Rootkit |
T1021.004 |
SSH |
T1027.005 |
Indicator Removal from Tools |
T1036.004 |
Masquerade Task or Service |
T1037 |
Boot or Logon Initialization Scripts |
T1037.004 |
RC Scripts |
T1040 |
Network Sniffing |
T1057 |
Process Discovery |
T1059.001 |
PowerShell |
T1059.003 |
Windows Command Shell |
(First 12 of 57 ATT&CK-mapped techniques.)
Related Pages
- Mitre Attack — the framework this page's data is drawn from
- Ke3Chang — China-linked actor, same attribution class
- Mustang Panda — China-linked actor, same attribution class
- Earth Lusca — China-linked actor, same attribution class
Provenance
Stub generated from MITRE ATT&CK G1048 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.