Threat Actor ๐จ๐ณ China
UNC3886
UNC3886 is an advanced cyber espionage group with unique capabilities in how they operate on-network as well as the tools they utilize in their campaigns. UNC3886 has been observed targeting firewall and virtualization technologies which lack EDR support. Their ability to manipulate firewall firmware and exploit a zero-day indicates they have curated a deeper-level of understanding of such technologies. UNC3886 has modified publicly available malware, specifically targeting *nix operating systems.
Indicators of Compromise 29
Domain mail[.]io Domain openmail[.]pro Domain tutamail[.]com Filename /bin/fgfm Filename /etc/rc.d/init.d/grub-rommon Filename /lib/libseconfd.so Filename /opt/.ICEauthority Filename /pkg/bin/dhcpd_show_issu_status Filename /pkg/bin/hd Filename /usr/bin/acpid Filename /usr/sbin/acppid Filename /var/log/.tacplus.acct Filename /var/tmp/audit Filename /var/tmp/ping Filename BridgeAgent Filename attacker-cert3 Filename backdoor-ssh Filename helpdesk Filename zabbix_agent.service SHA-1 13f0c2a598e3aa63856c032a96b110aed963f0e8 SHA-1 1682b652a15bde732489f22809b0b7594c228fd3 SHA-1 36005f5e4398a1c62a2a9271eddfcc1b44b1ad00 SHA-1 5ba1242050b5b447052b210788a5a25593d6987d SHA-1 955cd45a2f6f226a2fdf44b329af1c8dde90cb38 SHA-1 b149fa3a34bd585e7a674a4fd9538437bd06f514 SHA-1 be6b27f429324a4af05a310d8ec9635e37c68a94 IP 1[.]2[.]3[.]4 IP 144[.]31[.]1[.]252 IP 8[.]8[.]8[.]8
MITRE ATT&CK TTPs 25
T1021.001 T1027 T1036 T1040 T1046 T1055 T1059 T1059.001 T1070.006 T1071.001 T1078.002 T1082 T1083 T1090 T1095 T1098.002 T1105 T1110.001 T1136.001 T1543.001 T1556.004 T1566 T1573.004 T1583 T1588
Remote Desktop Protocol
Lateral Movement
Obfuscated Files or Information
Defense Evasion
Masquerading
Defense Evasion
Network Sniffing
Credential Access
Network Service Discovery
Discovery
Process Injection
Defense Evasion
Command and Scripting Interpreter
Execution
PowerShell
Execution
Timestomp
Defense Evasion
Web Protocols
Command And Control
Domain Accounts
Defense Evasion
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Proxy
Command And Control
Non-Application Layer Protocol
Command And Control
Additional Email Delegate Permissions
Persistence
Ingress Tool Transfer
Command And Control
Password Guessing
Credential Access
Local Account
Persistence
Launch Agent
Persistence
Network Device Authentication
Credential Access
Phishing
Initial Access
T1573.004
Acquire Infrastructure
Resource Development
Obtain Capabilities
Resource Development
Source Articles
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
A China-nexus cyber espionage group tracked as Fire Ant has expanded its operations to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts, enabling credential theft, traffic interception, and suppression of security telemetry. The group deployed custom malware including TacTap, a library injector targeting the tac_plus authentication process, and BridgeAgent, a Linux backdoor disguised as a Zabbix agent. The attackers manipulated router configurations to hide malicious GRE tunnels and exfiltrated packet captures to external FTP servers, while also obfuscating stolen credentials using XOR encryption. The campaign shows strong overlap with UNC3886, though definitive attribution remains unconfirmed.
hacker-news ยท2d ago
Chinese Fire Ant hackers turn Cisco routers into spying platforms
The Chinese state-sponsored threat actor Fire Ant has shifted tactics to compromise Cisco IOS XR routers, TACACS servers, and Linux management systems, turning routers into surveillance platforms via concealed GRE tunnels. The group deployed a custom backdoor named 'BridgeAgent', disguised as a Zabbix agent, enabling reverse shells and execution of additional payloads. Fire Ant uses stealthy persistence mechanisms, suppresses syslog messages, and exfiltrates network traffic PCAPs to FTP servers, aiming to map and access high-value networks through a 'target behind the target' strategy. The group's activity overlaps with UNC3886 but shows distinct implementation differences.
bleeping-computer ยท2d ago
Opening the Black Box: Agentless Threat Detection for Virtual Appliances
FortiGate virtual appliances are being actively targeted by multiple threat actors due to their internet-facing nature and elevated privileges. Attackers exploit vulnerabilities such as CVE-2026-24858, CVE-2024-55591, and CVE-2022-41328 to gain access, create backdoor accounts, manipulate certificates, and establish lateral movement. These activities are often obscured by log deletion and weak configurations, making detection difficult without agentless visibility.
wiz