Threat Actor ๐Ÿ‡จ๐Ÿ‡ณ China

UNC3886

UNC3886 is an advanced cyber espionage group with unique capabilities in how they operate on-network as well as the tools they utilize in their campaigns. UNC3886 has been observed targeting firewall and virtualization technologies which lack EDR support. Their ability to manipulate firewall firmware and exploit a zero-day indicates they have curated a deeper-level of understanding of such technologies. UNC3886 has modified publicly available malware, specifically targeting *nix operating systems.

Indicators of Compromise 29

MITRE ATT&CK TTPs 25

Source Articles

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
A China-nexus cyber espionage group tracked as Fire Ant has expanded its operations to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts, enabling credential theft, traffic interception, and suppression of security telemetry. The group deployed custom malware including TacTap, a library injector targeting the tac_plus authentication process, and BridgeAgent, a Linux backdoor disguised as a Zabbix agent. The attackers manipulated router configurations to hide malicious GRE tunnels and exfiltrated packet captures to external FTP servers, while also obfuscating stolen credentials using XOR encryption. The campaign shows strong overlap with UNC3886, though definitive attribution remains unconfirmed.
hacker-news ยท2d ago
Chinese Fire Ant hackers turn Cisco routers into spying platforms
The Chinese state-sponsored threat actor Fire Ant has shifted tactics to compromise Cisco IOS XR routers, TACACS servers, and Linux management systems, turning routers into surveillance platforms via concealed GRE tunnels. The group deployed a custom backdoor named 'BridgeAgent', disguised as a Zabbix agent, enabling reverse shells and execution of additional payloads. Fire Ant uses stealthy persistence mechanisms, suppresses syslog messages, and exfiltrates network traffic PCAPs to FTP servers, aiming to map and access high-value networks through a 'target behind the target' strategy. The group's activity overlaps with UNC3886 but shows distinct implementation differences.
bleeping-computer ยท2d ago
Opening the Black Box: Agentless Threat Detection for Virtual Appliances
FortiGate virtual appliances are being actively targeted by multiple threat actors due to their internet-facing nature and elevated privileges. Attackers exploit vulnerabilities such as CVE-2026-24858, CVE-2024-55591, and CVE-2022-41328 to gain access, create backdoor accounts, manipulate certificates, and establish lateral movement. These activities are often obscured by log deletion and weak configurations, making detection difficult without agentless visibility.
wiz